Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
Use Microsoft vendor hub and Frontpage Server Extensions product page to widen CVE-2006-0015 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2003-0822, CVE-2002-0692 and CVE-2001-0341 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.