CVE-1999-0561

CRITICAL

IIS has the #exec function enabled for Server Side Include (SSI) files.

Affects 0 products across 1 vendor.

BCS7.53
CVSS 2.010.0
EPSS7.6%
Percentile94th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 1999. A critical vulnerability affects Files systems (CVE-1999-0561). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-1999-GLOBAL-307940-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-1999-0561?
This vulnerability was disclosed in 1999. A critical vulnerability affects Files systems (CVE-1999-0561). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-1999-0561?
CVE-1999-0561 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 7.6%.
Is CVE-1999-0561 actively exploited?
No confirmed active exploitation of CVE-1999-0561 as of 2026-05-30.
How do I remediate CVE-1999-0561?
Priority: MEDIUM.
What systems are affected by CVE-1999-0561?
CVE-1999-0561 affects: Files.
Vulnerability Details
CVE IDCVE-1999-0561
BSIDBS-1999-GLOBAL-307940-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published1999-01-01
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

IIS has the #exec function enabled for Server Side Include (SSI) files.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: IIS has the #exec function enabled for Server Side Include (SSI) files. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Files —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 10076 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashfddf89368031965630069511a36f2827321c1f5c4a9ec72dafb9bc79e95766bcc5422b8c36da38e3f6912d32ea57b235aa9b9fe22e43644d8d5cbb839dd585cb
Related CVEs affecting Files
CVE-1999-0498 10.0 TFTP is not running in a restricted directory, allowing a remote attacker to ... CVE-1999-0937 10.0 BNBForm allows remote attackers to read arbitrary files via the automessage h... CVE-2025-23953 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite ... CVE-2025-32510 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ova... CVE-2024-6500 10.0 The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vuln...
View all Files CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →