AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2000-1166

HIGH · CVSS 7.5 EPSS 1.63%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2001-01-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2000-1166
Severity
HIGH
CVSS
7.5
EPSS
1.63%

Original NVD Description

Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.