PT-2026-37238 · Proftpd · Proftpd

Xs1Kveroa

·

Published

2026-05-05

·

Updated

2026-05-13

·

CVE-2026-44331

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProFTPD versions prior to 1.3.9a 7666224
Description A SQL injection issue exists in the sqltab fetch clients cb() function within contrib/mod wrap2 sql.c. When the "UseReverseDNS on" setting is enabled, a remote attacker can inject arbitrary SQL commands by using a crafted domain name during a reverse DNS lookup, as the hostname is passed into SQL queries without being escaped. The exploitability of this issue may be limited by the character restrictions inherent to DNS names.
Recommendations Update to version 1.3.9a 7666224 or later. Disable the "UseReverseDNS" setting to prevent the processing of reverse DNS lookups.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2026-06340
CVE-2026-44331
OESA-2026-2264
OESA-2026-2265
OESA-2026-2266
OESA-2026-2267
OESA-2026-2268

Affected Products

Proftpd