[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
Exploit-DB published a PoC for CVE-2026-42167, post-authentication SQL injection in ProFTPD mod_sql leading to remote code execution.
Exploit-DB entry 52658 provides a remote exploit for CVE-2026-42167, a SQL injection in ProFTPD's mod_sql module that is reachable after authentication and can lead to remote code execution. Successful exploitation requires valid credentials on the target FTP service.
- CVE-2026-42167: SQL injection in ProFTPD mod_sql module
- Post-authentication requirement limits exposure to credentialed users
- SQLi escalates to remote code execution
- PoC exploit published as Exploit-DB entry 52658
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-42167 | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). NVD description · AI analysis pending | 8.1 | 7% | PoC ×3 |
| — |
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
This source does not provide full text. Read it at exploit-db.com.