Cross-Site Scripting Vulnerabilities in Apache Geronimo 1.0
CVE-2006-0254

Currently unrated

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
18 January 2006

What is CVE-2006-0254?

Apache Geronimo 1.0 is affected by multiple cross-site scripting vulnerabilities that allow remote attackers to inject arbitrary web script or HTML. This can occur through manipulation of the time parameter to cal2.jsp, as well as via any invalid parameter. When the log file is accessed through the Web-Access-Log viewer, these injected scripts can be executed, potentially compromising the integrity of users' sessions and exposing sensitive data.

References

EPSS Score

45% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.