CVE-2006-0015
Summary
| CVE | CVE-2006-0015 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-04-11 23:02:00 UTC |
| Updated | 2018-10-19 15:42:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Frontpage Server Extensions | 2002 | All | All | All |
| Application | Microsoft | Frontpage Server Extensions | 2002 | All | All | All |
| Application | Microsoft | Sharepoint Team Services | All | All | All | All |
| Application | Microsoft | Sharepoint Team Services | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft SharePoint Team Services Input Validation Holes Permit Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | securitytracker.com | Patch |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| SecurityTracker.com Archives - Microsoft FrontPage Server Extensions Input Validation Holes Permit Cross-Site Scripting Attacks | SECTRACK | securitytracker.com | Patch |
| Microsoft FrontPage Server Extensions Cross-Site Scripting Vulnerability | BID | www.securityfocus.com | Exploit, Patch |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Microsoft Security Bulletin MS06-017 - Moderate | Microsoft Docs | MS | docs.microsoft.com | |
| Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting - CXSecurity.com | SREASON | securityreason.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 404 - Not Found | MISC | www.argeniss.com | Exploit, Patch, Vendor Advisory |
| Microsoft FrontPage Server Extensions Cross-Site Scripting - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.