CVE-2006-1547
HIGH KEVApache Struts <1.2.9 - DoS
Title source: llmDescription
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
References (10)
Scores
CVSS v3
7.5
EPSS
0.1547
EPSS Percentile
94.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation Intel
CISA KEV
2022-01-21
VulnCheck KEV
2022-01-21
InTheWild.io
2022-01-21
ENISA EUVD
EUVD-2022-3054
Classification
CWE
CWE-749
Status
draft
Affected Products (2)
apache/struts
< 1.2.9
struts/struts
< 1.2.9Maven
Timeline
Published
Mar 30, 2006
KEV Added
Jan 21, 2022
Tracked Since
Feb 18, 2026