cbcvebase.
CVE-2006-6578
published 2006-12-15

CVE-2006-6578: Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to…

PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.97%
93.4th percentile
Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com when it is in a web directory with certain permissions.

Affected

1 ranges
VendorProductVersion rangeFixed in
microsoftinternet_information_services
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.