CVE-2014-8110: XSS
Apache ActiveMQ is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-8110?
CVE-2014-8110 is a vulnerability in Apache ActiveMQ that allows remote attackers to execute script in a victim's web browser.
How severe is CVE-2014-8110?
CVE-2014-8110 has a severity rating of 4.3 (medium).
What software versions are affected by CVE-2014-8110?
CVE-2014-8110 affects Apache ActiveMQ versions 5.0.0 to 5.10.0.
How can CVE-2014-8110 be exploited?
CVE-2014-8110 can be exploited by using a specially-crafted URL to execute script in a victim's web browser.
Are there any references for CVE-2014-8110?
Yes, you can find references for CVE-2014-8110 in the following documents: [1] [2] [3].