SQL Injection Vulnerability in ProFTPD by ProFTPD Project
CVE-2026-44331
8.1HIGH
What is CVE-2026-44331?
In ProFTPD versions prior to 1.3.9a, a vulnerability exists in the sqltab_fetch_clients_cb() function within contrib/mod_wrap2_sql.c. This flaw allows remote attackers to perform SQL injection attacks through specially crafted domain names during reverse DNS lookups. When the 'UseReverseDNS on' setting is enabled, attacker-controlled hostnames can be integrated into SQL queries without proper escaping. Although the constraints of DNS name characters may limit exploitation, it poses a significant risk to affected systems.
Affected Version(s)
ProFTPD 0 <= 1.3.9a
