VDB

CVE-2006-0254

CVE-2006-0254 PUBLISHED CVSS 4.300000190734863 MEDIUM

Reported by mitre · Published January 18, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.

Risk Scores

CVSS 2.0
4.300000190734863

Affected Products

VendorProductVersions
n/an/an/a
Mavengeronimo:geronimo-console-standard0, 0
n/an/an/a, n/a, n/a

Timeline

  • Jan 18, 2006 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Jul 28, 2022 CVE Updated
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›