AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-0254

MEDIUM · CVSS 4.3 EPSS 32.25%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-01-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-0254
Severity
MEDIUM
CVSS
4.3
EPSS
32.25%
Apache

Original NVD Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.