Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache ActiveMQ 'createDestination.action'跨站脚本攻击漏洞
Vulnerability Description
ActiveMQ是美国Apache软件基金会所研发的一套开源的消息中间件,它支持Java消息服务、集群、Spring Framework等。 Apache ActiveMQ的createDestination.action存在跨站脚本攻击漏洞。远程认证用户可以借助队列操作中的JMSDestination参数,注入任意的web脚本和HTML。
CVSS Information
N/A
Vulnerability Type
N/A