Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 04 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ProFTPD SQL Injection via USER Command in mod_sql Leading to Remote Code Execution |
Sat, 02 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ProFTPD SQL Injection via USER Command in mod_sql Leading to Remote Code Execution |
Sat, 02 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ProFTPD mod_sql Remote Code Execution via Username Injection |
Fri, 01 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 01 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). |
| References |
|
Fri, 01 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 29 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ProFTPD mod_sql Remote Code Execution via Username Injection |
Tue, 28 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). | |
| First Time appeared |
Proftpd
Proftpd proftpd |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Proftpd
Proftpd proftpd |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-01T18:22:51.500Z
Reserved: 2026-04-24T00:00:00.000Z
Link: CVE-2026-42167
Updated: 2026-05-01T18:22:51.500Z
Status : Awaiting Analysis
Published: 2026-04-28T23:16:20.610
Modified: 2026-05-01T19:16:30.723
Link: CVE-2026-42167
No data.
OpenCVE Enrichment
Updated: 2026-05-04T15:15:03Z