Release date:
Updated on:
Affected Systems:
OpenX 2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 61650
CVE (CAN) ID: CVE-2013-4211
OpenX is an open-source advertising server written in PHP.
The downloadable zip file of OpenX 2.8.10 has a backdoor vulnerability. This vulnerability is caused by a backdoor in the damaged OpenX Source code package. After being exploited, attackers can execute arbitrary PHP code.
<* Source: Heiko Weber
Link: http://secunia.com/advisories/54274/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OpenX
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://blog.openx.org/08/important-update-for-openx-source-2-8-10-users/
Http://forum.openx.org/index.php? Showtopic = 503521628