mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
[POC] CVE-2026-42167 — CVE-2026-42167-PoC
ProFTPD SQL injection PoC
[POC] CVE-2026-42167 — CVE-2026-42167-Exploit
Python exploit for CVE-2026-42167 (ProFTPD mod_sql). Features automated file scanning and timing-based blind data exfiltration.
[POC] CVE-2026-42167 — CVE-2026-42167-PoC
Pre-Auth RCE in ProFTPD via mod_sql is_escaped_text() bypass (CVE-2026-42167)
[POC] CVE-2026-42167 — proftpd-CVE-2026-42167-analysis
Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass).
[POC] CVE-2026-42167 — proftpd-CVE-2026-42167-poc
POCs to demonstrate CVE-2026-42167 in ProFTPD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free