PoC Index

CVE-2001-1044

HIGH 7.5EPSS 6.9%

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
6.94% chance of exploitation in the next 30 days, 94th percentile
Published
2002-02-02
Updated
2024-08-08

ExploitDB entries (1)

References

Related