CVE-2006-0254
unknown
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
1.0
Description
Apache Geronimo console 1.0 vulnerable to cross-site scripting
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Apache Geronimo 1.0 - Error Page Cross-Site Scripting
Source code queued for fetch โ refresh in a moment.
Apache Tomcat / Geronimo 1.0 - 'Sample Script cal2.jsp?time' Cross-Site Scripting
Source code queued for fetch โ refresh in a moment.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | geronimo:geronimo-console-standard | <1.1 | 1.1 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2006-0254
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24158
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24159
- https://geronimo.apache.org/GMOxDOC11/release-notes-11txt.html
- https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&styleName=Html&projectId=10220&Create=Create
- https://issues.apache.org/jira/secure/attachment/12322088/GERONIMO-1474.patch
- http://issues.apache.org/jira/browse/GERONIMO-1474
- http://rhn.redhat.com/errata/RHSA-2008-0630.html
- http://secunia.com/advisories/18485
- http://secunia.com/advisories/31493
- http://svn.apache.org/viewvc/geronimo
- http://svn.apache.org/viewvc?view=revision&revision=372322
- http://www.oliverkarow.de/research/geronimo_css.txt
- http://www.redhat.com/support/errata/RHSA-2008-0261.html
- http://www.securityfocus.com/archive/1/421996/100/0/threaded
- http://www.securityfocus.com/bid/16260
- http://www.vupen.com/english/advisories/2006/0217
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.