VDB
CVE-2001-0333
CVE-2001-0333
PUBLISHED
CVSS 7.5 HIGH
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.
EPSS 84.55% · 99.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
84.55%
99.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| microsoft | internet_information_server | 4.0, 0 |
Timeline
- Jun 27, 2001 CVE Published
- Jan 8, 2011 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Aug 8, 2024 CVE Updated
- Dec 17, 2024 EPSS Score
- Feb 6, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Mar 17, 2025 EPSS Score
- Mar 22, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
References
- MS01-026 vendor-advisory
- oval:org.mitre.oval:def:1051 vdb
- CA-2001-12 third-party-advisory
- iis-url-decoding(6534) vdb
- oval:org.mitre.oval:def:37 vdb
- oval:org.mitre.oval:def:78 vdb
- 2708 vdb
- 20010515 NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability mailing-list
- oval:org.mitre.oval:def:1018 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2001-0333 advisory