peter bassill · operator
$ cve CVE-2001-1290 JSON

CVE-2001-1290 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.5% (pctl 94)

Patch early

A public exploit exists.

Description

admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS6.49% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2001-06-28
Last modified2026-06-16

Affected (1)

VendorProduct
active web suite technologiesactive classifieds

Public exploits

SourceTitleDate
exploit-dbActive Classifieds 1.0 - Arbitrary Code Execution2001-06-28

References

→ the Explorer  ·  watch your stack  ·  NVD