Bug 2466878 (CVE-2026-44331) - CVE-2026-44331 ProFTPD: mod_wrap2_sql: SQL injection via reverse DNS hostname
Summary: CVE-2026-44331 ProFTPD: mod_wrap2_sql: SQL injection via reverse DNS hostname
Keywords:
Status: NEW
Alias: CVE-2026-44331
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2466898 2466899
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-05 20:02 UTC by OSIDB Bzimport
Modified: 2026-05-06 19:02 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-05 20:02:42 UTC
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When "UseReverseDNS on" is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect exploitability.


Note You need to log in before you can comment on or make changes to this bug.