ProFTPD mod_sql before 1.3.10rc1 contains a remote code execution caused by unsafe username handling with SQL backend commands in USER request logging expansions, letting remote attackers execute arbitrary code, exploit requires SQL backend allowing commands.
id: CVE-2026-42167
info:
name: ProFTPD mod_sql - Preauth User Backdoor
author: pussycat0x
sev
...