CVE-2006-0254
Apache Geronimo console 1.0 vulnerable to cross-site scripting
EPSS 32.2%
Description
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer. Version 1.1 contains fixes for these issues.
How to fix CVE-2006-0254
To remediate CVE-2006-0254, upgrade the affected package to a fixed version below.
- Maven/geronimo:geronimo-console-standard—upgrade to 1.1 or later
Is CVE-2006-0254 being exploited?
Moderate — EPSS is 32.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.1