KEVIntel
7.5
CVSS
High

CVE-2006-1547

PUBLISHED

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Apache Software Foundation
Product
Struts
Published
Mar 30, 2006
EPSS

Description

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

apache cisa

CVSS scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2.0 7.8

AV:N/AC:L/Au:N/C:N/I:N/A:C

Exploitation status

Exploited in the wild

Recorded 2022-01-21 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 21, 2022

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel