High severityNVD Advisory· Published Mar 30, 2006· Updated Jun 16, 2026
CVE-2006-1546
CVE-2006-1546
Description
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
struts:strutsMaven | < 1.2.9 | 1.2.9 |
Affected products
2Patches
Vulnerability mechanics
References
15- github.com/advisories/GHSA-vf8g-mpmw-qv87ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2006-1546ghsaADVISORY
- issues.apache.org/bugzilla/show_bug.cginvdWEB
- lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlnvdWEB
- mail-archives.apache.org/mod_mbox/struts-dev/200601.mbox/%[email protected]%3eghsaWEB
- mail-archives.apache.org/mod_mbox/struts-dev/200601.mbox/%3cdr169r%24623%242%40sea.gmane.org%3envdWEB
- mail-archives.apache.org/mod_mbox/struts-user/200601.mbox/%3c20060121221800.15814.qmail%40web32607.mail.mud.yahoo.com%3envdWEB
- mail-archives.apache.org/mod_mbox/struts-user/200601.mbox/%[email protected]%3eghsaWEB
- secunia.com/advisories/19493nvdWEB
- secunia.com/advisories/20117nvdWEB
- securitytracker.com/idnvdWEB
- struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.htmlnvdWEB
- www.securityfocus.com/bid/17342nvdWEB
- www.vupen.com/english/advisories/2006/1205nvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/25612nvdWEB
News mentions
0No linked articles in our index yet.