CVE-2001-1044 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 6.9% (pctl 94)
Patch early
A public exploit exists.
Description
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 6.94% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-01-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| basilix | basilix webmail |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Basilix Webmail 0.9.7 - Incorrect File Permissions | 2001-01-11 |
References
→ the Explorer · watch your stack · NVD