CVE-2014-8110
published 2015-02-12CVE-2014-8110: Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
7.08%
93.5th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| debian | activemq | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
ghsa·2022-05-14
CVE-2014-8110 [MEDIUM] CWE-79 Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
OSV
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
osv·2022-05-14
CVE-2014-8110 [MEDIUM] Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Debian
CVE-2014-8110: activemq - Multiple cross-site scripting (XSS) vulnerabilities in the web based administrat...
vendor_debian·2014·CVSS 4.3
CVE-2014-8110 [MEDIUM] CVE-2014-8110: activemq - Multiple cross-site scripting (XSS) vulnerabilities in the web based administrat...
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://activemq.apache.org/security-advisories.data/CVE-2014-8110-announcement.txthttp://seclists.org/oss-sec/2015/q1/427http://secunia.com/advisories/62649http://www.securityfocus.com/bid/72511https://exchange.xforce.ibmcloud.com/vulnerabilities/100724https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttp://activemq.apache.org/security-advisories.data/CVE-2014-8110-announcement.txthttp://seclists.org/oss-sec/2015/q1/427http://secunia.com/advisories/62649http://www.securityfocus.com/bid/72511https://exchange.xforce.ibmcloud.com/vulnerabilities/100724https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
2015-02-12
Published