CVE-2006-0015
Microsoft FrontPage Server Extensions and SharePoint Team Services - Cross-Site Scripting via fpadmdll.dll Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0015. PoCs published by Esteban Martinez Fayo.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Microsoft FrontPage Server Extensions by injecting arbitrary script code into the 'operation' parameter of a POST request. The vulnerability arises due to insufficient input sanitization, allowing execution of malicious scripts in the context of a victim's browser session.
Description
Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Microsoft FrontPage Server Extensions by injecting arbitrary script code into the 'operation' parameter of a POST request. The vulnerability arises due to insufficient input sanitization, allowing execution of malicious scripts in the context of a victim's browser session.