CVE-2026-42167

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
Configurations

No configuration.

History

01 May 2026, 19:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/01/13 -

01 May 2026, 16:16

Type Values Removed Values Added
References
  • () https://www.openwall.com/lists/oss-security/2026/05/01/4 -
Summary (en) mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). (en) mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

01 May 2026, 12:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/01/4 -

30 Apr 2026, 15:48

Type Values Removed Values Added
References () https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc - () https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc -

28 Apr 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 23:16

Updated : 2026-05-01 19:16


NVD link : CVE-2026-42167

Mitre link : CVE-2026-42167

CVE.ORG link : CVE-2026-42167


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')