Vulnerabilities
Vulnerable Software
Apache:  >> Activemq  >> 5.8.0  Security Vulnerabilities
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
CVSS Score
7.5
EPSS Score
0.087
Published
2015-08-14
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
4.3
EPSS Score
0.052
Published
2015-02-12
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.
CVSS Score
4.3
EPSS Score
0.01
Published
2014-02-05
Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
CVSS Score
4.3
EPSS Score
0.043
Published
2013-07-20


Contact Us

Shodan ® - All rights reserved