CVE-2015-1830

Apache ActiveMQ 5.x-5.11.1 Directory Traversal Shell Upload

Title source: metasploit

Description

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/48181
exploitdb WORKING POC
remotewindows
https://www.exploit-db.com/exploits/40857
metasploit WORKING POC EXCELLENT
by David Jorm, Erik Wynter · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/apache_activemq_traversal_upload.rb

Scores

EPSS 0.8602
EPSS Percentile 99.4%

Details

CWE
CWE-22
Status published
Products (23)
apache/activemq 5.0.0
apache/activemq 5.1.0
apache/activemq 5.2.0
apache/activemq 5.3.0
apache/activemq 5.3.1
apache/activemq 5.3.2
apache/activemq 5.4.0
apache/activemq 5.4.1
apache/activemq 5.4.2
apache/activemq 5.4.3
... and 13 more
Published Aug 19, 2015
Tracked Since Feb 18, 2026