CVE-2006-1546
published 2006-03-30CVE-2006-1546: Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a…
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.14%
92.7th percentile
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | <= 1.2.8 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Struts vulnerable to Improper Input Validation
osv·2022-05-01
CVE-2006-1546 [HIGH] Apache Struts vulnerable to Improper Input Validation
Apache Struts vulnerable to Improper Input Validation
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
GHSA
Apache Struts vulnerable to Improper Input Validation
ghsa·2022-05-01
CVE-2006-1546 [HIGH] CWE-20 Apache Struts vulnerable to Improper Input Validation
Apache Struts vulnerable to Improper Input Validation
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
Red Hat
struts bypass validation
vendor_redhat·2006-03-22·CVSS 7.5
CVE-2006-1546 [HIGH] struts bypass validation
struts bypass validation
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-1546 struts bypass validation
bugzilla·2008-01-28·CVSS 7.5
CVE-2006-1546 [HIGH] CVE-2006-1546 struts bypass validation
CVE-2006-1546 struts bypass validation
Common Vulnerabilities and Exposures assigned an identifier CVE-2006-1546 to the following vulnerability:
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
References:
http://mail-archives.apache.org/mod_mbox/struts-user/200601.mbox/%[email protected]%3e
http://mail-archives.apache.org/mod_mbox/struts-dev/200601.mbox/%[email protected]%3e
http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html
http://issues.apache.org/bugzilla/show_bug.c
Bugzilla
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
bugzilla·2006-08-15·CVSS 7.5
CVE-2006-1546 [HIGH] CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
Fixes needed for FC6
http://errata.devel.redhat.com/errata/showrequest.cgi?advisory=3594
-- Additional comment from [email protected] on 2006-05-03 11:41 EST --
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0281.html
Bugzilla
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
bugzilla·2006-03-31·CVSS 7.5
CVE-2006-1546 [HIGH] CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
+++ This bug was initially created as a clone of Bug #187542 +++
Struts 1.2.9 has been released wich fixes 3 security issues.
* CVE-2006-1546 Validation always skipped with Globals.CANCEL_KEY.
* CVE-2006-1547 DOS attack, application hack.
* CVE-2006-1548 XSS vulnerability in LookupDispatchAction.
http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html
This issue should also affect RHAPS1
Discussion:
Product reached end of lifecycle for security updates
Bugzilla
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
bugzilla·2006-03-31·CVSS 7.5
CVE-2006-1546 [HIGH] CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
Struts 1.2.9 has been released wich fixes 3 security issues.
* CVE-2006-1546 Validation always skipped with Globals.CANCEL_KEY.
* CVE-2006-1547 DOS attack, application hack.
* CVE-2006-1548 XSS vulnerability in LookupDispatchAction.
http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html
This issue should also affect RHAPS1
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0
http://issues.apache.org/bugzilla/show_bug.cgi?id=38374http://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://mail-archives.apache.org/mod_mbox/struts-dev/200601.mbox/%3cdr169r%24623%242%40sea.gmane.org%3ehttp://mail-archives.apache.org/mod_mbox/struts-user/200601.mbox/%3c20060121221800.15814.qmail%40web32607.mail.mud.yahoo.com%3ehttp://secunia.com/advisories/19493http://secunia.com/advisories/20117http://securitytracker.com/id?1015856http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.htmlhttp://www.securityfocus.com/bid/17342http://www.vupen.com/english/advisories/2006/1205https://exchange.xforce.ibmcloud.com/vulnerabilities/25612http://issues.apache.org/bugzilla/show_bug.cgi?id=38374http://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://mail-archives.apache.org/mod_mbox/struts-dev/200601.mbox/%3cdr169r%24623%242%40sea.gmane.org%3ehttp://mail-archives.apache.org/mod_mbox/struts-user/200601.mbox/%3c20060121221800.15814.qmail%40web32607.mail.mud.yahoo.com%3ehttp://secunia.com/advisories/19493http://secunia.com/advisories/20117http://securitytracker.com/id?1015856http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.htmlhttp://www.securityfocus.com/bid/17342http://www.vupen.com/english/advisories/2006/1205https://exchange.xforce.ibmcloud.com/vulnerabilities/25612
2006-03-30
Published