peter bassill · operator
$ cve CVE-2006-0254 JSON

CVE-2006-0254 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 32.2% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS32.25% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2006-01-18
Last modified2026-06-16

Affected (1)

VendorProduct
apachegeronimo

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD