6.8
CVSSv2

CVE-2013-7376

Published: 14/05/2014 Updated: 15/05/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote malicious users to hijack the authentication of administrators, as demonstrated by requests that conduct directory traversal attacks via the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-3514.

Vulnerable Product Search on Vulmon Subscribe to Product

openx openx 2.8.10

Exploits

Advisory ID: HTB23155 Product: OpenX Vendor: OpenX Vulnerable Version(s): 2810 and probably prior Tested Version: 2810 Vendor Notification: May 8, 2013 Vendor Patch: June 28, 2013 Public Disclosure: July 3, 2013 Vulnerability Type: PHP File Inclusion [CWE-98], Cross-Site Scripting [CWE-79] CVE References: CVE-2013-3514, CVE-2013-3515 Risk Le ...