Back

CVE-2001-0333

Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

Published: Jun 27, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft internet_information_server *
microsoft internet_information_server 4.0

GitHub Security Advisory GHSA-j59q-fjq9-v929

Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 90.77%

Top 0% most likely to be exploited

Threat Score 67.2 / 100

Data Sources

NVD EPSS GitHub