CVE-2006-1681
NUCLEICherokee HTTPD <0.5 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.
Nuclei Templates (1)
Cherokee HTTPD <=0.5 - Cross-Site Scripting
MEDIUMby geeknik
References (7)
Scores
EPSS
0.0026
EPSS Percentile
49.0%
Details
Status
published
Products (13)
cherokee/cherokee_httpd
0.1
cherokee/cherokee_httpd
0.1.5
cherokee/cherokee_httpd
0.1.6
cherokee/cherokee_httpd
0.2
cherokee/cherokee_httpd
0.2.5
cherokee/cherokee_httpd
0.2.6
cherokee/cherokee_httpd
0.2.7
cherokee/cherokee_httpd
0.4.6
cherokee/cherokee_httpd
0.4.7
cherokee/cherokee_httpd
0.4.8
... and 3 more
Published
Apr 11, 2006
Tracked Since
Feb 18, 2026