CVE-2009-4098
29.11.2009, 13:08
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.Enginsight
Vendor | Product | Version |
---|---|---|
openx | openx | 𝑥 ≤ 2.8.1 |
openx | openx | 2.4 |
openx | openx | 2.6.1 |
openx | openx | 2.6.3 |
openx | openx | 2.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References