Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows...
Vulnerability Description
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-0506
Credits & Attribution
No credits recorded in the NVD database.
References
- http://online.securityfocus.com/archive/1/242541
- http://marc.info/?l=bugtraq&m=99802093532233&w=2
- http://www.securityfocus.com/bid/3190
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6984
- http://www.ciac.org/ciac/bulletins/l-132.shtml
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.