Vulnerability Name: | CVE-2006-1546 (CCN-25612) | ||||||||
Assigned: | 2006-03-30 | ||||||||
Published: | 2006-03-30 | ||||||||
Updated: | 2023-02-13 | ||||||||
Summary: | Struts could allow a remote attacker to bypass security restrictions. If an attacker sends a request with a "org.apache.struts.taglib.html.Constants.CANCEL" parameter, the attacker could cause validation to be canceled without being detected by Struts applications that do not check for isCancelled(). This could allow the attacker to bypass security restrictions and gain unauthorized access to restricted content. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-1546 Source: CCN Type: ASF Bugzilla Bug 38374 Validation always skipped with Globals.CANCEL_KEY Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: RHSA-2006-0281 struts security update for Red Hat Application Server Source: CCN Type: SA19493 Struts Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1015856 Struts Bugs May Let Remote Users Bypass Validation, Conduct Cross-Site Scripting Attacks, and Deny Service Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: Apache Struts Project Web page Welcome to Apache Struts! Source: CCN Type: Struts Release Notes 6.1 Release Notes - Version 1.2.9 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-17342 Apache Struts Multiple Remote Vulnerabilities Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN struts-iscancelled-security-bypass(25612) Source: SUSE Type: SUSE-SR:2006:010 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |