4.3
CVSSv2

CVE-2012-4989

Published: 22/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote malicious users to inject arbitrary web script or HTML via the parent parameter in an info action.

Vulnerable Product Search on Vulmon Subscribe to Product

openx openx 2.8.10

Exploits

source: wwwsecurityfocuscom/bid/55860/info OpenX is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or ...
OpenX version 2810 suffers from cross site scripting and remote SQL injection vulnerabilities ...