CVE Vulnerabilities

CVE-2006-1546

Published: Mar 30, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a org.apache.struts.taglib.html.Constants.CANCEL parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.

Affected Software

Name Vendor Start Version End Version
Struts Apache * 1.2.8 (including)
Red Hat Application Server 3AS RedHat *
Red Hat Application Server v2 4AS RedHat *
Libstruts1.2-java Ubuntu dapper *
Libstruts1.2-java Ubuntu devel *
Libstruts1.2-java Ubuntu edgy *
Libstruts1.2-java Ubuntu feisty *

References