mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 28 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). | |
| First Time appeared |
Proftpd
Proftpd proftpd |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Proftpd
Proftpd proftpd |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-28T22:09:41.090Z
Reserved: 2026-04-24T00:00:00.000Z
Link: CVE-2026-42167
No data.
Status : Received
Published: 2026-04-28T23:16:20.610
Modified: 2026-04-28T23:16:20.610
Link: CVE-2026-42167
No data.
OpenCVE Enrichment
Updated: 2026-04-28T23:30:05Z
Weaknesses