CVE-2001-1044 describes a critical vulnerability in Basilix Webmail 0.9.7beta and potentially other versions, where sensitive files like *.class and *.inc are stored under the web document root without access restrictions. This allows unauthenticated remote attackers to directly access these files, potentially exposing confidential information such as MySQL usernames and passwords. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a severe risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score of 92/100 further emphasizes its high criticality. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an exploit (EDB-20538) demonstrating incorrect file permissions exists on ExploitDB. Despite its age, the lack of community discussion or media coverage is typical for many CVEs, but the presence of a public exploit indicates its potential for abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.7_betaCPE matchmatch criteria | cpe:2.3:a:basilix:basilix_webmail:0.9.7_beta:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.