CVE-2026-44331 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: May 5, 2026
ProFTPD - SQL Injection
Published: May 5, 2026Updated: May 5, 2026Remote Exploitable
Overview
ProFTPD <= 1.3.9a before 7666224 contains a SQL injection caused by unescaped attacker-supplied hostnames in reverse DNS lookups in sqltab_fetch_clients_cb(), letting remote attackers inject arbitrary SQL commands, exploit requires UseReverseDNS enabled.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Remote attackers can execute arbitrary SQL commands, potentially compromising the database and sensitive data.
Mitigation
Update to version 7666224 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-44331
- Severity
- High
- CVSS Score
- 8.1
- Type
- sql_injection
- Status
- new
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H