Back

CVE-2001-0506

Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.

Published: Sep 20, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft internet_information_server 4.0
microsoft internet_information_services 5.0

GitHub Security Advisory GHSA-vjg8-57hm-fxmj

Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 30.00%

Top 2% most likely to be exploited

Threat Score 37.8 / 100

Data Sources

NVD EPSS GitHub