peter bassill · operator
$ cve CVE-2001-1044 JSON

CVE-2001-1044 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 6.9% (pctl 94)

Patch early

A public exploit exists.

Description

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS6.94% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2001-01-11
Last modified2026-06-16

Affected (1)

VendorProduct
basilixbasilix webmail

Public exploits

SourceTitleDate
exploit-dbBasilix Webmail 0.9.7 - Incorrect File Permissions2001-01-11

References

→ the Explorer  ·  watch your stack  ·  NVD