CVE-2001-1138 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 10.3% (pctl 96)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 10.26% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-09-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| randy parker | power up html |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Power Up HTML 0.8033 Beta - Directory Traversal Arbitrary File Disclosure | 2001-09-07 |
References
→ the Explorer · watch your stack · NVD