ZeroHour
Exploit-DBpublished ()ingested 1

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

mediumExploit / PoCimportance 45CVE-2026-42167
AI summary · glm-5.3-flash

Exploit-DB published a PoC for CVE-2026-42167, post-authentication SQL injection in ProFTPD mod_sql leading to remote code execution.

Exploit-DB entry 52658 provides a remote exploit for CVE-2026-42167, a SQL injection in ProFTPD's mod_sql module that is reachable after authentication and can lead to remote code execution. Successful exploitation requires valid credentials on the target FTP service.

  • CVE-2026-42167: SQL injection in ProFTPD mod_sql module
  • Post-authentication requirement limits exposure to credentialed users
  • SQLi escalates to remote code execution
  • PoC exploit published as Exploit-DB entry 52658
VendorsProFTPD
OrganizationsExploit-DB

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-42167
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

NVD description · AI analysis pending
8.17% PoC ×3
  • proftpd proftpd
Full article

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

This source does not provide full text. Read it at exploit-db.com.