CVE-2013-7149
EXPLOITEDRevive Adserver <3.0.2 & OpenX Source <=2.8.11 - SQL Injection
Title source: llmExploitation Summary
CVE-2013-7149 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
http://www.kreativrauschen.com/blog/2013/12/18/zero-day-vulnerability-in-openx-source-2-8-11-and-revive-adserver-3-0-1/
Vendor Advisory x_refsource_confirm
http://www.revive-adserver.com/security/REVIVE-SA-2013-001/
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/530471/30/0/threaded
Scores
EPSS
0.0201
EPSS Percentile
78.8%
Details
VulnCheck KEV
2013-12-20
CWE
CWE-89
Status
published
Products (4)
openx/openx
2.8.10
openx/openx
< 2.8.11
revive-adserver/revive_adserver
3.0.0
revive-adserver/revive_adserver
< 3.0.1
Published
Dec 28, 2013
Tracked Since
Feb 18, 2026