<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aproftpdproftpd/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 25 Aug 2026 16:37:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aproftpdproftpd/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-42167: Remote Code Execution via ProFTPD mod_sql</title><link>https://feed.craftedsignal.io/briefs/2026-08-proftpd-sqli/</link><pubDate>Tue, 25 Aug 2026 16:37:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-proftpd-sqli/</guid><description>An authenticated SQL injection vulnerability (CVE-2026-42167) in the ProFTPD mod_sql module allows attackers to achieve remote code execution, with a functional exploit now publicly available.</description><content:encoded><![CDATA[<p>CVE-2026-42167 is a critical vulnerability affecting the ProFTPD server, specifically within the mod_sql module. This vulnerability allows an authenticated user to perform SQL injection attacks, which can be further weaponized to achieve remote code execution on the underlying host. The vulnerability was disclosed alongside a functional exploit (EDB-52658), significantly increasing the risk to environments where ProFTPD is deployed with SQL-based authentication or logging enabled. Defenders should prioritize patching or disabling the mod_sql module if it is not strictly required, as the public availability of the exploit simplifies the path to system compromise for attackers who have obtained valid FTP credentials.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution with the privileges of the ProFTPD service. This can lead to full system compromise, data exfiltration, and lateral movement within the network. The scope of impact is limited to servers running ProFTPD with the mod_sql module enabled.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply vendor patches for CVE-2026-42167 across all affected ProFTPD instances immediately.</li>
<li>Disable the mod_sql module in the ProFTPD configuration file if it is not necessary for business operations.</li>
<li>Monitor authentication logs for suspicious patterns originating from authenticated FTP users, specifically those interacting with database-backed authentication components.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>