CVE-2006-1548
published 2006-03-30CVE-2006-1548: Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.33%
91.8th percentile
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | <= 1.2.8 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cross-site scripting in Apache Struts
ghsa·2022-05-01
CVE-2006-1548 [LOW] CWE-79 Cross-site scripting in Apache Struts
Cross-site scripting in Apache Struts
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
OSV
Cross-site scripting in Apache Struts
osv·2022-05-01
CVE-2006-1548 [LOW] Cross-site scripting in Apache Struts
Cross-site scripting in Apache Struts
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
Red Hat
struts LookupDispatchAction XSS
vendor_redhat·2006-03-22·CVSS 4.3
CVE-2006-1548 [MEDIUM] CWE-79 struts LookupDispatchAction XSS
struts LookupDispatchAction XSS
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-1548 struts LookupDispatchAction XSS
bugzilla·2008-01-28·CVSS 4.3
CVE-2006-1548 [MEDIUM] CVE-2006-1548 struts LookupDispatchAction XSS
CVE-2006-1548 struts LookupDispatchAction XSS
Common Vulnerabilities and Exposures assigned an identifier CVE-2006-1548 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
References:
http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html
http://issues.apache.org/bugzilla/show_bug.cgi?id=38749
http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html
http://www.securityfocus.com/bid/17342
http://www.frsirt.com/english/advisories/2006/1205
http://securitytrack
Bugzilla
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
bugzilla·2006-08-15·CVSS 7.5
CVE-2006-1546 [HIGH] CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
Fixes needed for FC6
http://errata.devel.redhat.com/errata/showrequest.cgi?advisory=3594
-- Additional comment from [email protected] on 2006-05-03 11:41 EST --
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0281.html
Bugzilla
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
bugzilla·2006-03-31·CVSS 7.5
CVE-2006-1546 [HIGH] CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
+++ This bug was initially created as a clone of Bug #187542 +++
Struts 1.2.9 has been released wich fixes 3 security issues.
* CVE-2006-1546 Validation always skipped with Globals.CANCEL_KEY.
* CVE-2006-1547 DOS attack, application hack.
* CVE-2006-1548 XSS vulnerability in LookupDispatchAction.
http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html
This issue should also affect RHAPS1
Discussion:
Product reached end of lifecycle for security updates
Bugzilla
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
bugzilla·2006-03-31·CVSS 7.5
CVE-2006-1546 [HIGH] CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
CVE-2006-1546 Struts multiple issues (CVE-2006-1547, CVE-2006-1548)
Struts 1.2.9 has been released wich fixes 3 security issues.
* CVE-2006-1546 Validation always skipped with Globals.CANCEL_KEY.
* CVE-2006-1547 DOS attack, application hack.
* CVE-2006-1548 XSS vulnerability in LookupDispatchAction.
http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html
This issue should also affect RHAPS1
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0
http://issues.apache.org/bugzilla/show_bug.cgi?id=38749http://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://secunia.com/advisories/19493http://secunia.com/advisories/20117http://securitytracker.com/id?1015856http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.htmlhttp://www.securityfocus.com/bid/17342http://www.vupen.com/english/advisories/2006/1205https://exchange.xforce.ibmcloud.com/vulnerabilities/25614https://issues.apache.org/struts/browse/STR-2781http://issues.apache.org/bugzilla/show_bug.cgi?id=38749http://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://secunia.com/advisories/19493http://secunia.com/advisories/20117http://securitytracker.com/id?1015856http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.htmlhttp://www.securityfocus.com/bid/17342http://www.vupen.com/english/advisories/2006/1205https://exchange.xforce.ibmcloud.com/vulnerabilities/25614https://issues.apache.org/struts/browse/STR-2781
2006-03-30
Published