VYPR

Juser

by Joomlaequipment

CVEs (2)

  • CVE-2007-6038Nov 20, 2007
    risk 0.05cvss epss 0.21

    PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2009-2601Jul 27, 2009
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profile action to index.php.