CVE
- Id
- 17650
- CVE No.
- CVE-2006-1546
- Status
- Candidate
- Description
- Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a "org.apache.struts.taglib.html.Constants.CANCEL" parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
- Phase
- Assigned (20060330)
- Votes
- None (candidate not yet proposed)
- Comments