SQL Injection Vulnerability in ProFTPD by ProFTPD Project
CVE-2026-44331

8.1HIGH

Key Information:

Vendor

Proftpd

Status
Vendor
CVE Published:
5 May 2026

What is CVE-2026-44331?

In ProFTPD versions prior to 1.3.9a, a vulnerability exists in the sqltab_fetch_clients_cb() function within contrib/mod_wrap2_sql.c. This flaw allows remote attackers to perform SQL injection attacks through specially crafted domain names during reverse DNS lookups. When the 'UseReverseDNS on' setting is enabled, attacker-controlled hostnames can be integrated into SQL queries without proper escaping. Although the constraints of DNS name characters may limit exploitation, it poses a significant risk to affected systems.

Affected Version(s)

ProFTPD 0 <= 1.3.9a

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.