EIP-2026-114772

PRE-CVE

ProFTPd 1.3.0 (OpenSUSE) - 'mod_ctrls' Local Stack Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114772. PoCs published by Michael Domberg.

AI-analyzed exploit summary This exploit targets a stack overflow vulnerability in ProFTPd's mod_ctrls module by sending a maliciously crafted buffer to a Unix domain socket, leading to remote code execution. The payload includes shellcode that binds a shell to port 19091.

Description

ProFTPd 1.3.0 (OpenSUSE) - 'mod_ctrls' Local Stack Overflow

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michael Domberg · perllocalunix
https://www.exploit-db.com/exploits/10044

This exploit targets a stack overflow vulnerability in ProFTPd's mod_ctrls module by sending a maliciously crafted buffer to a Unix domain socket, leading to remote code execution. The payload includes shellcode that binds a shell to port 19091.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ProFTPd with mod_ctrls (OpenSuSE 10.2 on i686)
No auth needed
Prerequisites: Access to the Unix domain socket path · ProFTPd with mod_ctrls enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026