Vulnerability Name: | CVE-2006-1548 (CCN-25614) | ||||||||
Assigned: | 2006-03-30 | ||||||||
Published: | 2006-03-30 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-1548 Source: CCN Type: ASF Bugzilla Bug 38749 [extras] XSS vulnerability in LookupDispatchAction Source: CONFIRM Type: UNKNOWN http://issues.apache.org/bugzilla/show_bug.cgi?id=38749 Source: SUSE Type: UNKNOWN SUSE-SR:2006:010 Source: CCN Type: RHSA-2006-0281 struts security update for Red Hat Application Server Source: CCN Type: SA19493 Struts Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 19493 Source: SECUNIA Type: UNKNOWN 20117 Source: CCN Type: SECTRACK ID: 1015856 Struts Bugs May Let Remote Users Bypass Validation, Conduct Cross-Site Scripting Attacks, and Deny Service Source: SECTRACK Type: UNKNOWN 1015856 Source: CCN Type: Apache Struts Project Web page Downloading Struts Source: CCN Type: Struts Release Notes 6.1 Release Notes - Version 1.2.9 Source: CONFIRM Type: UNKNOWN http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html Source: BID Type: UNKNOWN 17342 Source: CCN Type: BID-17342 Apache Struts Multiple Remote Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-1205 Source: XF Type: UNKNOWN struts-lookupmap-xss(25614) Source: XF Type: UNKNOWN struts-lookupmap-xss(25614) Source: CONFIRM Type: UNKNOWN https://issues.apache.org/struts/browse/STR-2781 Source: CCN Type: IBM Security Bulletin 6910171 (Integration Designer) Multiple CVEs affect IBM Integration Designer Source: SUSE Type: SUSE-SR:2006:010 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |