CVE-2014-8110

Apache ActiveMQ 5.x < 5.10.1 - Cross-Site Scripting in Web Administration Console

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-8110. PoCs published by tafamace.

AI-analyzed exploit summary The provided code is a simple Java stub that prints command-line arguments and does not demonstrate any exploit functionality for CVE-2014-8110. It lacks offensive techniques or vulnerability-specific logic.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploits (1)

nomisec STUB 1 stars
by tafamace · poc
https://github.com/tafamace/CVE-2014-8110

The provided code is a simple Java stub that prints command-line arguments and does not demonstrate any exploit functionality for CVE-2014-8110. It lacks offensive techniques or vulnerability-specific logic.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2015/q1/427
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72511
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62649
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100724

Scores

EPSS 0.0391
EPSS Percentile 88.6%

Details

CWE
CWE-79
Status published
Products (19)
apache/activemq 5.0.0
apache/activemq 5.1.0
apache/activemq 5.2.0
apache/activemq 5.3.0
apache/activemq 5.3.1
apache/activemq 5.3.2
apache/activemq 5.4.0
apache/activemq 5.4.1
apache/activemq 5.4.2
apache/activemq 5.4.3
... and 9 more
Published Feb 12, 2015
Tracked Since Feb 18, 2026