First published: Fri Feb 14 2020(Updated: )
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Open edX | =2.8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4211 is rated as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2013-4211, upgrade OpenX Ad Server to a version that does not include the vulnerable flowplayer-3.1.1.min.js library.
CVE-2013-4211 specifically affects OpenX Ad Server version 2.8.10.
Exploitation of CVE-2013-4211 allows attackers to execute arbitrary PHP code on the affected system, potentially leading to full system compromise.
Yes, CVE-2013-4211 is considered relatively easy to exploit, making it crucial to address promptly.