CVE-2006-1548: XSS
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1548?
CVE-2006-1548 has been classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2006-1548?
To fix CVE-2006-1548, upgrade Apache Struts to version 1.2.9 or later, which addresses this vulnerability.
What does CVE-2006-1548 affect?
CVE-2006-1548 affects Apache Struts versions prior to 1.2.9, allowing for injection of arbitrary web scripts or HTML.
What are the risks associated with CVE-2006-1548?
The risks associated with CVE-2006-1548 include potential data theft, session hijacking, and malicious redirection of users.
Who is vulnerable to CVE-2006-1548?
Web applications using vulnerable versions of Apache Struts are at risk from CVE-2006-1548, enabling remote attackers to exploit XSS.