peter bassill · operator
$ cve CVE-2001-0333 JSON

CVE-2001-0333 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 90.8% (pctl 100)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS90.77% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2001-06-27
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet information server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD