Summary
OpenX is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately validate user- supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation other attacks
are also possible.
The issue affects OpenX 2.8.1 and prior.
Solution
Reportedly, the vendor fixed this issue in OpenX 2.8.2. Symantec has not confirmed this information. Please contact the vendor for details.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2009-4098 -
CVSS Base Score: 6.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
Related Vulnerabilities
- Apache Rave User Information Disclosure Vulnerability
- Adobe ColdFusion HTTP Response Splitting Vulnerability
- Andy's PHP Knowledgebase Multiple Cross-Site Scripting Vulnerabilities
- APC PowerChute Network Shutdown HTTP Response Splitting Vulnerability
- Aardvark Topsites <= 4.2.2 Remote File Inclusion Vulnerability