CVE-2006-1547

CVE Published 2006-03-30
Related Vendor(s) apache
Related Product(s) commons_beanutils, struts
Exploitation Reported (CISA KEV) 2022-01-21
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References