CVE-2013-7149

EXPLOITED

Revive Adserver <3.0.2 & OpenX Source <=2.8.11 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-7149 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.

References (3)

Core 3

Scores

EPSS 0.0201
EPSS Percentile 78.8%

Details

VulnCheck KEV 2013-12-20
CWE
CWE-89
Status published
Products (4)
openx/openx 2.8.10
openx/openx < 2.8.11
revive-adserver/revive_adserver 3.0.0
revive-adserver/revive_adserver < 3.0.1
Published Dec 28, 2013
Tracked Since Feb 18, 2026