CVE Database
/

CVE-2006-0015

Back to search

CVE-2006-0015

Published: Apr 11, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.

VendorProductVersions

n/a

n/a

affected
n/a

References

fpse-html-xss(25537)
vdb-entry
x_refsource_XF
17452
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:1748
vdb-entry
signature
x_refsource_OVAL
19623
third-party-advisory
x_refsource_SECUNIA
704
third-party-advisory
x_refsource_SREASON
1015896
vdb-entry
x_refsource_SECTRACK
ADV-2006-1322
vdb-entry
x_refsource_VUPEN
1015895
vdb-entry
x_refsource_SECTRACK
MS06-017
vendor-advisory
x_refsource_MS

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now