CVE-2013-7149
28.12.2013, 04:53
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.
Vendor | Product | Version |
---|---|---|
openx | openx | 𝑥 ≤ 2.8.11 |
openx | openx | 2.8.10 |
revive-adserver | revive_adserver | 𝑥 ≤ 3.0.1 |
revive-adserver | revive_adserver | 3.0.0 |
𝑥
= Vulnerable software versions
References