Description:
CVE-2026-42167 mod_sql in ProFTPD before 1.3.9a allows remote attackers
to execute arbitrary code via a username, in scenarios where there is
logging of USER requests with an expansion such as %U, and the SQL
backend allows commands (e.g., COPY TO PROGRAM).
CVE-2026-44331 a SQL injection vulnerability in
sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote
attacker to inject arbitrary SQL commands via a crafted domain name that
is accessed in a reverse DNS lookup. When "UseReverseDNS on" is enabled,
the attacker-supplied hostname is passed unescaped into SQL queries. The
character restrictions of DNS names may affect
- https://bugs.mageia.org/show_bug.cgi?id=35445
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BEM6GPOFEILUHBP4D2KWIUHVXL5546WE/
- https://www.cve.org/CVERecord?id=CVE-2026-42167
- https://www.cve.org/CVERecord?id=CVE-2026-44331
- 9/core/proftpd-1.3.8c-1.2.mga9
Publication date:12 Jun 2026
Get the latest Linux and open source security news straight to your inbox.