CVE-2006-1681

NUCLEI

Cherokee HTTPD <0.5 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.

Nuclei Templates (1)

Cherokee HTTPD <=0.5 - Cross-Site Scripting
MEDIUMby geeknik

Scores

EPSS 0.0026
EPSS Percentile 49.0%

Details

Status published
Products (13)
cherokee/cherokee_httpd 0.1
cherokee/cherokee_httpd 0.1.5
cherokee/cherokee_httpd 0.1.6
cherokee/cherokee_httpd 0.2
cherokee/cherokee_httpd 0.2.5
cherokee/cherokee_httpd 0.2.6
cherokee/cherokee_httpd 0.2.7
cherokee/cherokee_httpd 0.4.6
cherokee/cherokee_httpd 0.4.7
cherokee/cherokee_httpd 0.4.8
... and 3 more
Published Apr 11, 2006
Tracked Since Feb 18, 2026