CVE-2001-1334

Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.

Scoring

CVSS base score
0.35
EPSS probability
6.96%
Published
2003-04-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs