CVE-2001-1020

edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function.

Scoring

CVSS base score
0.07
EPSS probability
1.46%
Published
2002-03-09
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs