Logo
componentproftpd
Name
proftpd
Version
1.3.8d
Type
library
Description
-
Licenses
GPL-2.0+
PURL
-
CPE
cpe:2.3:a:proftpd:proftpd:1.3.8d:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.3.9a

Patches#


#
Title
Author
Resolve
1
Issue #2052: When resolving any variable whose value is
TJ Saunders <tj@castaglia.org>
CVE-2026-42167

Vulnerabilities#


Name
Analysis
Description
Patched
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
Exploitable
mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.