CVE-2010-0684
published 2010-04-05CVE-2010-0684: Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
4.28%
90.0th percentile
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | <= 5.3.0 | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache ActiveMQ up to 5.3.0 JMSDestination cross site scripting (XFDB-57397 / SBV-25218)
vuldb·2026-05-05·CVSS 3.5
CVE-2010-0684 [LOW] Apache ActiveMQ up to 5.3.0 JMSDestination cross site scripting (XFDB-57397 / SBV-25218)
A vulnerability, which was classified as problematic, has been found in Apache ActiveMQ. Impacted is an unknown function. This manipulation of the argument JMSDestination causes cross site scripting.
This vulnerability is registered as CVE-2010-0684. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
OSV
Cross-site scripting in Apache ActiveMQ
osv·2022-05-02
CVE-2010-0684 [LOW] Cross-site scripting in Apache ActiveMQ
Cross-site scripting in Apache ActiveMQ
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
GHSA
Cross-site scripting in Apache ActiveMQ
ghsa·2022-05-02
CVE-2010-0684 [LOW] CWE-79 Cross-site scripting in Apache ActiveMQ
Cross-site scripting in Apache ActiveMQ
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Red Hat
ActiveMQ: XSS in createDestination
vendor_redhat·2010-02-17·CVSS 3.5
CVE-2010-0684 [LOW] CWE-79 ActiveMQ: XSS in createDestination
ActiveMQ: XSS in createDestination
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Statement: Not vulnerable. Apache ActiveMQ is not shipped with any supported Red Hat products.
No detection rules found.
arXiv
A Match Made in Heaven? AI-driven Matching of Vulnerabilities and Security Unit Tests
arxiv_fulltext·2026-01-22
A Match Made in Heaven? AI-driven Matching of Vulnerabilities and Security Unit Tests
A Match Made in Heaven? AI-driven Matching of Vulnerabilities and Security Unit Tests
Emanuele Iannone
0000-0001-7489-9969
Hamburg University of Technology
Hamburg
Germany
[email protected]
Quang-Cuong Bui
0000-0001-6072-9213
Hamburg University of Technology
Hamburg
Germany
[email protected]
Riccardo Scandariato
0000-0003-3591-7671
Hamburg University of Technology
Hamburg
Germany
[email protected]
showcomments
showcommentsfalse
peerreview
peerreviewfalse
gray75gray.25
gray50gray.5
gray40gray.6
gray30gray.7
gray25gray.75
gray20gray.8
gray15gray.85
gray10gray.9
gray05gray.95
redbgHTMLF2968F
greenbgHTMLCDE4AE
ghdiffredbgHTMLffccce
ghdiffgreenbgHTMLabefbc
goalcolorHTMLfffff2
rqboxcolorHTMLf2f2ff
rqanswercolorHTMLfaf9f5
takeawaycolorHTMLf2fff2
darkgreenHTML009B55
[1]
Bugzilla
CVE-2010-0684 ActiveMQ: XSS in createDestination
bugzilla·2010-04-09·CVSS 3.5
CVE-2010-0684 [LOW] CVE-2010-0684 ActiveMQ: XSS in createDestination
CVE-2010-0684 ActiveMQ: XSS in createDestination
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0684 to
the following vulnerability:
Cross-site scripting (XSS) vulnerability in createDestination.action
in Apache ActiveMQ before 5.3.1 allows remote authenticated users to
inject arbitrary web script or HTML via the JMSDestination parameter
in a queue action.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0684
[2] http://www.securityfocus.com/archive/1/archive/1/510419/100/0/threaded
[3] http://www.rajatswarup.com/CVE-2010-0684.txt
[4] http://activemq.apache.org/activemq-531-release.html
[5] https://issues.apache.org/activemq/browse/AMQ-2613
[6] https://issues.apache.org/activemq/browse/AMQ-2625
[7] http://www.securityfocus.com/bid/39119
[8] ht
http://activemq.apache.org/activemq-531-release.htmlhttp://secunia.com/advisories/39223http://securitytracker.com/id?1023778http://www.rajatswarup.com/CVE-2010-0684.txthttp://www.securityfocus.com/archive/1/510419/100/0/threadedhttp://www.securityfocus.com/bid/39119https://exchange.xforce.ibmcloud.com/vulnerabilities/57397https://issues.apache.org/activemq/browse/AMQ-2613https://issues.apache.org/activemq/browse/AMQ-2625http://activemq.apache.org/activemq-531-release.htmlhttp://secunia.com/advisories/39223http://securitytracker.com/id?1023778http://www.rajatswarup.com/CVE-2010-0684.txthttp://www.securityfocus.com/archive/1/510419/100/0/threadedhttp://www.securityfocus.com/bid/39119https://exchange.xforce.ibmcloud.com/vulnerabilities/57397https://issues.apache.org/activemq/browse/AMQ-2613https://issues.apache.org/activemq/browse/AMQ-2625
2010-04-05
Published