CVE-2003-0224
Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 18.27% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet information services
- Source
- cve@mitre.org
References
- http://marc.info/?l=ntbugtraq&m=105431767100944&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A483
- http://marc.info/?l=ntbugtraq&m=105431767100944&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A483
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.