First published: Thu Mar 30 2006(Updated: )
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Struts | <=1.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1548 has been classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2006-1548, upgrade Apache Struts to version 1.2.9 or later, which addresses this vulnerability.
CVE-2006-1548 affects Apache Struts versions prior to 1.2.9, allowing for injection of arbitrary web scripts or HTML.
The risks associated with CVE-2006-1548 include potential data theft, session hijacking, and malicious redirection of users.
Web applications using vulnerable versions of Apache Struts are at risk from CVE-2006-1548, enabling remote attackers to exploit XSS.