CVE-2006-0015
Published Apr 11, 2006
Last updated 6 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
- Source
- secure@microsoft.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:frontpage_server_extensions:2002:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7E274F0-F1B8-4C3D-961B-80B92830ABF9" }, { "criteria": "cpe:2.3:a:microsoft:sharepoint_team_services:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83ADDF33-AC0A-43F1-8250-EC84221F02D6" } ], "operator": "OR" } ] } ]