CVE-2006-0254

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/01/2006
Last modified:
03/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:geronimo:1.0:*:*:*:*:*:*:*