peter bassill · operator
$ cve CVE-2006-0026 JSON

CVE-2006-0026 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 89.3% (pctl 100)

Patch early

A public exploit exists.

Description

Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS89.26% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2006-07-11
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftinternet information server
microsoftinternet information services

Public exploits

SourceTitleDate
exploit-dbMicrosoft IIS - ASP Stack Overflow (MS06-034)2006-07-21

References

→ the Explorer  ·  watch your stack  ·  NVD