CVE-2001-1044
Last modified
CVE-2001-1044 is a vulnerability of currently unknown severity. Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.. EPSS estimates a 6.94% chance of exploitation in the next 30 days.
Description
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Basilix | Basilix Webmail | 0.9.7_beta |
References
- http://www.securityfocus.com/archive/1/155897Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/2198Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/155897Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/2198Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1044?
How severe is CVE-2001-1044?
How do I fix CVE-2001-1044?
Are you affected by CVE-2001-1044?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
