Back

CVE-2001-1138

Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.

Published: Sep 7, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
randy_parker power_up_html 0.8033_beta

GitHub Security Advisory GHSA-37mh-6cwh-pwc5

Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 10.26%

Top 5% most likely to be exploited

Threat Score 33.1 / 100

Data Sources

NVD EPSS GitHub