PT-2026-37238 · Proftpd · Proftpd
Xs1Kveroa
·
Published
2026-05-05
·
Updated
2026-05-13
·
CVE-2026-44331
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ProFTPD versions prior to 1.3.9a 7666224
Description
A SQL injection issue exists in the
sqltab fetch clients cb() function within contrib/mod wrap2 sql.c. When the "UseReverseDNS on" setting is enabled, a remote attacker can inject arbitrary SQL commands by using a crafted domain name during a reverse DNS lookup, as the hostname is passed into SQL queries without being escaped. The exploitability of this issue may be limited by the character restrictions inherent to DNS names.Recommendations
Update to version 1.3.9a 7666224 or later.
Disable the "UseReverseDNS" setting to prevent the processing of reverse DNS lookups.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proftpd