CVE-2006-0026 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 89.3% (pctl 100)
Patch early
A public exploit exists.
Description
Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 89.26% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-07-11 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | internet information server |
| microsoft | internet information services |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft IIS - ASP Stack Overflow (MS06-034) | 2006-07-21 |
References
- http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html
- http://secunia.com/advisories/21006
- http://securitytracker.com/id?1016466
- http://www.kb.cert.org/vuls/id/395588
- http://www.osvdb.org/27152
- http://www.securityfocus.com/bid/18858
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html
- http://www.vupen.com/english/advisories/2006/2752
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-034
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26796
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A435
- http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html
- http://secunia.com/advisories/21006
- http://securitytracker.com/id?1016466
- http://www.kb.cert.org/vuls/id/395588
- http://www.osvdb.org/27152
- http://www.securityfocus.com/bid/18858
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html
- http://www.vupen.com/english/advisories/2006/2752
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-034
→ the Explorer · watch your stack · NVD