CVE-2006-0026
45Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 85%
from disclosure to weapon10 days
Published on NVDJul 11
1st PoC+10d
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/2056⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-034http://secunia.com/advisories/21006http://securitytracker.com/id?1016466https://exchange.xforce.ibmcloud.com/vulnerabilities/26796https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A435http://www.kb.cert.org/vuls/id/395588http://www.osvdb.org/27152http://www.securityfocus.com/bid/18858http://www.us-cert.gov/cas/techalerts/TA06-192A.htmlhttp://www.vupen.com/english/advisories/2006/2752