4.3
CVSSv2

CVE-2013-3514

Published: 14/05/2014 Updated: 15/05/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in OpenX prior to 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot dot) in the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-7376. NOTE: this can be leveraged using CSRF to allow remote unauthenticated malicious users to read arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

openx openx 2.8.4

openx openx 2.8.3

openx openx 2.8.2

openx openx

openx openx 2.4.6

openx openx 2.4.5

openx openx 2.4.4

openx openx 2.4.11

openx openx 2.6.4

openx openx 2.6.3

openx openx 2.6.2

openx openx 2.6.1

openx openx 2.8.9

openx openx 2.8.7

openx openx 2.8.5

openx openx 2.8.1

openx openx 2.7.29

openx openx 2.4.9

openx openx 2.4.7

openx openx 2.4.10

openx openx 2.8.8

openx openx 2.8.6

openx openx 2.8

openx openx 2.6.5

openx openx 2.6.0

openx openx 2.4.8

openx openx 2.4

Exploits

Advisory ID: HTB23155 Product: OpenX Vendor: OpenX Vulnerable Version(s): 2810 and probably prior Tested Version: 2810 Vendor Notification: May 8, 2013 Vendor Patch: June 28, 2013 Public Disclosure: July 3, 2013 Vulnerability Type: PHP File Inclusion [CWE-98], Cross-Site Scripting [CWE-79] CVE References: CVE-2013-3514, CVE-2013-3515 Risk Le ...
OpenX version 2810 suffers from cross site scripting and local file inclusion vulnerabilities ...