CVE detail
CVE-2001-1159 — CVE-2001-1159
Published 2001-07-02 · Modified 2026-06-16 · Vendor squirrelmail · Product squirrelmail · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0364
EPSS probability
exploitation probability, 30d
89.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References