VYPR

junkie

by Junkie

CVEs (3)

  • CVE-2019-25749Jun 19, 2026
    risk 0.00cvss epss

    Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL…

  • CVE-2004-1281Jan 10, 2005
    risk 0.00cvss epss 0.01

    The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in a filename.

  • CVE-2004-1280Jan 10, 2005
    risk 0.00cvss epss 0.02

    The gui_popup_view_fly function in gui_tview_popup.c for junkie 0.3.1 allows remote malicious FTP servers to execute arbitrary commands via shell metacharacters in a filename.