Back

CVE-2001-1242

Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.

Published: Jul 17, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (12)

Vendor Product Version
steve_grimm un-cgi 1.0
steve_grimm un-cgi 1.1
steve_grimm un-cgi 1.2
steve_grimm un-cgi 1.3
steve_grimm un-cgi 1.4
steve_grimm un-cgi 1.5
steve_grimm un-cgi 1.6
steve_grimm un-cgi 1.6.1
steve_grimm un-cgi 1.6.2
steve_grimm un-cgi 1.7
steve_grimm un-cgi 1.8
steve_grimm un-cgi 1.9

GitHub Security Advisory GHSA-f369-6f6w-pr3f

Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.98%

Top 14% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub