CVE-2012-4989
OpenX <2.8.10 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary web script or HTML via the parent parameter in an info action.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge · textwebappsphp
https://www.exploit-db.com/exploits/37938
References (7)
Scores
EPSS
0.0315
EPSS Percentile
86.8%
Details
CWE
CWE-79
Status
published
Products (2)
openx/openx
n/a/n/a
Published
Oct 22, 2012
Tracked Since
Feb 18, 2026