Back to Database
Status published
Medium
CVE-2001-1334
Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator...
Vulnerability Description
Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-1334
Credits & Attribution
No credits recorded in the NVD database.
References
More from phpslash
View All →CVE-2009-0517
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier...
Critical
10
CVE-2005-4479
SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier...
High
7.5
CVE-2005-2257
The saveProfile function in PhpSlash 0.8.0 allows remote attackers to...
Critical
10
Affected Vendor
phpslash
View all reports →Affected Software
phpslash
Vulnerable Versions:
0.5.3.2, 0.6.1
Timeline
Official Publish:
April 2nd, 2003
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.