CVE-2013-5954
OpenX 2.8.x - Multiple Cross-Site Request Forgery Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertisers via admin/advertiser-delete.php, (3) banners via admin/banner-delete.php, (4) campaigns via admin/campaign-delete.php, (5) channels via admin/channel-delete.php, (6) affiliate websites via admin/affiliate-delete.php, or (7) zones via admin/zone-delete.php.
Múltiples vulnerabilidades de CSRF en OpenX 2.8.11 y anteriores permiten a atacantes remotos secuestrar la autenticación de administradores para solicitudes que eliminan (1) usuarios a través de admin/agency-user-unlink.php, (2) anunciantes a través de admin/advertiser-delete.php, (3) banners a través de admin/banner-delete.php, (4) campañas a través de admin/campaign-delete.php, (5) canales a través de admin/channel-delete.php, (6) sitios web afiliados a través de admin/affiliate-delete.php o (7) zonas a través de admin/zone-delete.php.
OpenX version 2.8.11 suffers from multiple cross site request forgery vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-09-27 CVE Reserved
- 2014-03-15 CVE Published
- 2014-03-15 First Exploit
- 2024-08-06 CVE Updated
- 2024-11-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2014/May/68 | Mailing List | |
http://www.revive-adserver.com/security/revive-sa-2014-001 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/532108/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/91889 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/39117 | 2014-03-15 | |
http://packetstormsecurity.com/files/125735 | 2024-08-06 | |
http://seclists.org/fulldisclosure/2014/Mar/270 | 2024-08-06 | |
http://www.securityfocus.com/bid/66251 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Revive-adserver Search vendor "Revive-adserver" | Revive Adserver Search vendor "Revive-adserver" for product "Revive Adserver" | <= 3.0.4 Search vendor "Revive-adserver" for product "Revive Adserver" and version " <= 3.0.4" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | <= 2.8.11 Search vendor "Openx" for product "Openx" and version " <= 2.8.11" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8 Search vendor "Openx" for product "Openx" and version "2.8" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.1 Search vendor "Openx" for product "Openx" and version "2.8.1" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.2 Search vendor "Openx" for product "Openx" and version "2.8.2" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.3 Search vendor "Openx" for product "Openx" and version "2.8.3" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.4 Search vendor "Openx" for product "Openx" and version "2.8.4" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.5 Search vendor "Openx" for product "Openx" and version "2.8.5" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.6 Search vendor "Openx" for product "Openx" and version "2.8.6" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.7 Search vendor "Openx" for product "Openx" and version "2.8.7" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.8 Search vendor "Openx" for product "Openx" and version "2.8.8" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.9 Search vendor "Openx" for product "Openx" and version "2.8.9" | - |
Affected
| ||||||
Openx Search vendor "Openx" | Openx Search vendor "Openx" for product "Openx" | 2.8.10 Search vendor "Openx" for product "Openx" and version "2.8.10" | - |
Affected
|