First published: Sat Nov 28 2009(Updated: )
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open edX | <=2.8.1 | |
Open edX | =2.4 | |
Open edX | =2.6.1 | |
Open edX | =2.6.3 | |
Open edX | =2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4098 is classified as a high severity vulnerability due to the potential for remote code execution.
To remediate CVE-2009-4098, upgrade OpenX adserver to version 2.8.2 or later, where the issue is addressed.
CVE-2009-4098 affects OpenX adserver versions 2.8.1 and earlier, allowing remote authenticated users to exploit file upload functionalities.
CVE-2009-4098 is an unrestricted file upload vulnerability that permits the execution of arbitrary code.
Yes, CVE-2009-4098 can be exploited remotely by authenticated users who have the necessary permissions to upload files.