OpenX kayıtları
openx üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %15,4
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2013-4211Silahlaştırılmış | A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remoopenx · openx · CWE-94 | Kritik9,8 | — | %70,7 | 14 Şub 2020 |
32İzleyin | CVE-2009-0291Kavram kanıtı | Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a ..openx · openx · CWE-22 | Yüksek7,5 | — | %7,0 | 27 Oca 2009 |
31İzleyin | CVE-2008-6163Kavram kanıtı | SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL commands via the banneridopenx · openx · CWE-89 | Yüksek7,5 | — | %2,4 | 20 Şub 2009 |
31İzleyin | CVE-2009-4830İstismar yok | Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator acopenx · openx · CWE-287 | Yüksek7,5 | — | %2,3 | 27 Nis 2010 |
31İzleyin | CVE-2012-4990İstismar yok | SQL injection vulnerability in admin/campaign-zone-link.php in OpenX 2.8.10 before revision 81823 allows remote attackers to execute arbitraopenx · openx · CWE-89 | Yüksek7,5 | — | %2,3 | 22 Eki 2012 |
31İzleyin | CVE-2013-7149İstismar yok | SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and Opopenx · openx · CWE-89 | Yüksek7,5 | — | %2,0 | 28 Ara 2013 |
30İzleyin | CVE-2009-4098Silahlaştırılmış | Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner openx · openx · CWE-20 | Orta6,0 | — | %18,7 | 29 Kas 2009 |
28İzleyin | CVE-2013-5954Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication oopenx · openx · CWE-352 | Orta6,8 | — | %3,1 | 25 Nis 2014 |
27İzleyin | CVE-2013-7376Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijackopenx · openx · CWE-352 | Orta6,8 | — | %1,3 | 14 May 2014 |
24İzleyin | CVE-2014-2230İstismar yok | Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to aopenx · openx | Orta5,8 | — | %2,0 | 23 Eki 2014 |
18İzleyin | CVE-2012-4989Kavram kanıtı | Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject aopenx · openx · CWE-79 | Orta4,3 | — | %4,4 | 22 Eki 2012 |
18İzleyin | CVE-2013-3515Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web scriptopenx · openx · CWE-79 | Orta4,3 | — | %4,2 | 29 Tem 2013 |
18İzleyin | CVE-2013-3514Kavram kanıtı | Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via aopenx · openx · CWE-22 | Orta4,3 | — | %3,3 | 14 May 2014 |
- CVE-2013-421160Bu hafta
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remo
KritikCVSS 9,8SilahlaştırılmışEPSS %71openx · openx14 Şub 2020
- CVE-2009-029132İzleyin
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a ..
YüksekCVSS 7,5Kavram kanıtıEPSS %7openx · openx27 Oca 2009
- CVE-2008-616331İzleyin
SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL commands via the bannerid
YüksekCVSS 7,5Kavram kanıtıEPSS %2openx · openx20 Şub 2009
- CVE-2009-483031İzleyin
Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator ac
YüksekCVSS 7,5İstismar yokEPSS %2openx · openx27 Nis 2010
- CVE-2012-499031İzleyin
SQL injection vulnerability in admin/campaign-zone-link.php in OpenX 2.8.10 before revision 81823 allows remote attackers to execute arbitra
YüksekCVSS 7,5İstismar yokEPSS %2openx · openx22 Eki 2012
- CVE-2013-714931İzleyin
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and Op
YüksekCVSS 7,5İstismar yokEPSS %2openx · openx28 Ara 2013
- CVE-2009-409830İzleyin
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner
OrtaCVSS 6,0SilahlaştırılmışEPSS %19openx · openx29 Kas 2009
- CVE-2013-595428İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication o
OrtaCVSS 6,8Kavram kanıtıEPSS %3openx · openx25 Nis 2014
- CVE-2013-737627İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack
OrtaCVSS 6,8Kavram kanıtıEPSS %1openx · openx14 May 2014
- CVE-2014-223024İzleyin
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to a
OrtaCVSS 5,8İstismar yokEPSS %2openx · openx23 Eki 2014
- CVE-2012-498918İzleyin
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject a
OrtaCVSS 4,3Kavram kanıtıEPSS %4openx · openx22 Eki 2012
- CVE-2013-351518İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web script
OrtaCVSS 4,3Kavram kanıtıEPSS %4openx · openx29 Tem 2013
- CVE-2013-351418İzleyin
Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a
OrtaCVSS 4,3Kavram kanıtıEPSS %3openx · openx14 May 2014