HIGH
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup
Published May 5, 2026
8.1
HIGHCVSS 3.1
EPSS 0.50%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.