VYPR
High severityNVD Advisory· Published Mar 30, 2006· Updated Jun 16, 2026

CVE-2006-1546

CVE-2006-1546

Description

Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
struts:strutsMaven
< 1.2.91.2.9

Affected products

2

Patches

Vulnerability mechanics

References

15

News mentions

0

No linked articles in our index yet.