Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.microsoft.com/technet/security/bulletin/MS06-017.mspx http://www.rtr.com/fpsupport/fpse_release_may_2_2006.htm http://marc.theaimsgroup.com/?l=bugtraq&m=114487846329000 http://www.vuxml.org/freebsd/c0171f59-ea8a-11da-be02-000c6ec775d9.html
Insight
The following packages are affected:
frontpage
mod_frontpage13
mod_frontpage20
mod_frontpage21
mod_frontpage22
CVE-2006-0015
Cross-site scripting (XSS) vulnerability in
_vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
Severity
Classification
-
CVE CVE-2006-0015 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities