Sploitus

Exploit for Unrestricted Upload of File with Dangerous Type in Apache Activemq

githubexploit Β· 2021-03-11

Exploit Code

README25 lines
## https://sploitus.com/exploit?id=3AE83A9C-B2D7-51A9-8970-D1B1D01C23D5
# CVE-2016-3088

Apache ActiveMQ Remote Code Execution Exploit

## Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

## Author

* Alexandre Aguiar ([@cyberaguiar](https://cyberaguiar.com))


## Exploit analysis

* [Analysis of Apache ActiveMQ Remote Code Execution Vulnerability (CVE-2016–3088)](https://medium.com/@knownsec404team/analysis-of-apache-activemq-remote-code-execution-vulnerability-cve-2016-3088-575f80924f30)

## References

* https://nvd.nist.gov/vuln/detail/CVE-2016-3088

## Disclaimer

The developer of this script are not responsible for any misuse of this exploit we only encourage the ethical use of this script and to be used only when authorized to do so during a penetration test or similar. Any damages or misuse of this script is the responsibility of the individuals who use them unethically or with the intent to damage property.