


Perceptive Security
SOC/SIEM Consultancy

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inje…
Published:
4 mei 2026 om 22:00:00
Alert date:
5 mei 2026 om 21:02:16
Source:
nvd.nist.gov
Network Infrastructure, Database & Storage
A SQL injection vulnerability exists in ProFTPD through version 1.3.9a in the sqltab_fetch_clients_cb() function within contrib/mod_wrap2_sql.c. The vulnerability allows remote attackers to inject arbitrary SQL commands via crafted domain names during reverse DNS lookups. The issue occurs when 'UseReverseDNS on' is enabled, causing attacker-supplied hostnames to be passed unescaped into SQL queries. Character restrictions of DNS names may limit exploitability. The vulnerability has been addressed in commit 7666224.
Technical details
Mitigation steps:
Affected products:
ProFTPD
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44331
https://github.com/proftpd/proftpd/commit/766622456440fbca33abd7927c523673a11d1ed1
https://github.com/proftpd/proftpd/issues/2057
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
