CVE-2013-4211
CRITICALOpenX Ad Server 2.8.10 - Remote Code Execution via Backdoor in flowplayer-3.1.1.min.js
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2013-4211.
PoCs published by Metasploit, egypt, Unknown, including Metasploit module exploits/multi/http/openx_backdoor_php.
AI-analyzed exploit summary This Metasploit module exploits a backdoor in OpenX Ad Server 2.8.10, allowing arbitrary PHP code execution via a POST request with a rot13'd and reversed payload. The vulnerability was introduced in the software between November 2012 and August 2013.
Description
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code
Exploits (2)
This Metasploit module exploits a backdoor in OpenX Ad Server 2.8.10, allowing arbitrary PHP code execution via a POST request with a rot13'd and reversed payload. The vulnerability was introduced in the software between November 2012 and August 2013.
This Metasploit module exploits a backdoor in OpenX Ad Server 2.8.10, allowing arbitrary PHP code execution via a single POST request with a ROT13-encoded and reversed payload. The vulnerability was introduced in versions distributed between November 2012 and August 2013.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H