CVE-2006-1547 is a denial-of-service vulnerability affecting Apache Struts versions prior to 1.2.9 when used with BeanUtils 1.7. Remote attackers can exploit this by crafting a multipart/form-data request that references a specific method, leading to resource exhaustion. This vulnerability carries a high CVSS score of 7.5 due to its network-based attack vector, low complexity, and potential for high availability impact. It is actively exploited, listed in CISA's KEV catalog, and has garnered significant community discussion, despite a lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.9CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.