First published: Tue Apr 11 2006(Updated: )
Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Team Services | ||
Microsoft FrontPage Server Extensions | =2002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0015 is rated as important due to its potential for unauthorized access and execution of arbitrary programs.
To mitigate CVE-2006-0015, it is recommended to apply the latest patches for Microsoft FrontPage Server Extensions and SharePoint Team Services.
CVE-2006-0015 allows remote attackers to execute cross-site scripting attacks, potentially leading to session hijacking and unauthorized account creation.
CVE-2006-0015 affects Microsoft FrontPage Server Extensions 2002 and Microsoft SharePoint Team Services.
You can detect vulnerability to CVE-2006-0015 by scanning your systems for the presence of unpatched Microsoft FrontPage Server Extensions 2002 or SharePoint Team Services.