// For flags

CVE-2013-7149

 

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.

Vulnerabilidad de inyección SQL en www / entrega / axmlrpc.php (también conocido como el XML-RPC invocación de entrega de script) en Revive Adserver antes de 3.0.2, y OpenX Fuente 2.8.11 y anteriores, permite a atacantes remotos ejecutar comandos SQL a través del parámetro de lo que a un método de XML-RPC.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-19 CVE Reserved
  • 2013-12-20 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-09-14 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openx
Search vendor "Openx"
Openx
Search vendor "Openx" for product "Openx"
<= 2.8.11
Search vendor "Openx" for product "Openx" and version " <= 2.8.11"
-
Affected
Openx
Search vendor "Openx"
Openx
Search vendor "Openx" for product "Openx"
2.8.10
Search vendor "Openx" for product "Openx" and version "2.8.10"
-
Affected
Revive-adserver
Search vendor "Revive-adserver"
Revive Adserver
Search vendor "Revive-adserver" for product "Revive Adserver"
<= 3.0.1
Search vendor "Revive-adserver" for product "Revive Adserver" and version " <= 3.0.1"
-
Affected
Revive-adserver
Search vendor "Revive-adserver"
Revive Adserver
Search vendor "Revive-adserver" for product "Revive Adserver"
3.0.0
Search vendor "Revive-adserver" for product "Revive Adserver" and version "3.0.0"
-
Affected