CVE-2016-3088
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- March 10, 2016
- Published Date
- June 01, 2016
- Last Updated
- February 07, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-02-10 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/apache_activemq_upload_jsp.rb | 2025-04-29 11:01:20 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2016/CVE-2016-3088.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
apache_activemq_upload_jsp
Type: metasploit • Created: Unknown
cl4ym0re/CVE-2016-3088
Type: github • Created: 2021-07-03 10:23:59 UTC • Stars: 3
vonderchild/CVE-2016-3088
Type: github • Created: 2021-03-12 17:12:09 UTC • Stars: 0
cyberaguiar/CVE-2016-3088
Type: github • Created: 2021-03-11 05:54:34 UTC • Stars: 5
pudiding/CVE-2016-3088
Type: github • Created: 2020-12-24 07:26:00 UTC • Stars: 0
Ma1Dong/ActiveMQ_putshell-CVE-2016-3088
Type: github • Created: 2020-07-31 09:06:15 UTC • Stars: 14