Vulnerabilities > CVE-2004-1280 - Remote Security vulnerability in Junkie FTP Client 0.3.1

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
junkie
critical

Summary

The gui_popup_view_fly function in gui_tview_popup.c for junkie 0.3.1 allows remote malicious FTP servers to execute arbitrary commands via shell metacharacters in a filename.

Vulnerable Configurations

Part Description Count
Application
Junkie
1