AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2006-7196

MEDIUM · CVSS 4.3 EPSS 72.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-05-10 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2006-7196
Severity
MEDIUM
CVSS
4.3
EPSS
72.17%
Apache

Original Filing — NVD Description

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.