Exploitation Summary
EIP tracks 1 public exploit for CVE-2001-1044. PoCs published by Tamer Sahin.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in basilix webmail v. 0.9.7b. The vulnerability allows remote users to retrieve configuration files containing MySQL authentication details due to improper webserver configuration.
Description
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
Exploits (1)
This is a writeup describing an information disclosure vulnerability in basilix webmail v. 0.9.7b. The vulnerability allows remote users to retrieve configuration files containing MySQL authentication details due to improper webserver configuration.