Skip to main content

CVE detail

CVE-2001-0901

Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by requesting the URL for the attachment.

CVSS 7.5 · HighBuzz score 8.02 OTX pulses

Buzz score

Why this CVE is surfacing

Buzz score total 8.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 0.0 · diversity 0.0 · KEV 0.0 · OTX 8.0 · PoC 0.0
Mention score
0.0
0 evidence mentions in the snapshot
Diversity score
0.0
0 sources across 0 categories
KEV score
0.0
No KEV entry observed
OTX score
8.0
2 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
0 source links · newest first

    Exploit code

    Public exploit repository references

    Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

    0 repository references · best confidence N/A · max 0 stars
    No public PoC repositories have been matched yet.

    Related records

    Similar CVEs

    6 related CVEs with shared weakness or product evidence
    • CVE-2026-63048

      The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

      CVSS 9.4 · Critical
      1 mention
    • CVE-2026-16451

      A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of…

      CVSS 2.1 · Low
      5 mentions
    • CVE-2026-16447

      A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument File…

      CVSS 5.5 · Medium
      6 mentions
    • CVE-2026-16332

      A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata…

      CVSS 5.5 · Medium
      6 mentions
    • CVE-2026-16331

      A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Mal…

      CVSS 5.5 · Medium
      6 mentions
    • CVE-2026-16330

      A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argume…

      CVSS 5.5 · Medium
      6 mentions