VulnerabilityModified
CVE-2001-1235
pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.
HIGH 7.5EPSS 4.57%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.57% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- derek leung/pslash
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html
- http://www.iss.net/security_center/static/7215.php
- http://www.kb.cert.org/vuls/id/847803Exploit, Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/3395Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html
- http://www.iss.net/security_center/static/7215.php
- http://www.kb.cert.org/vuls/id/847803Exploit, Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/3395Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.