#VU4352 SQL injection in Revive Adserver - CVE-2013-7149
Published: January 12, 2017 / Updated: March 11, 2017
Revive Adserver
OpenX Source
Description
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted HTTP request to the XML-RPC script using the "what" parameter and view, add, modify or delete information in the back-end database.
Successful exploitation may allow an attacker to gain unauthorized access to the vulnerable system.
Note: this vulnerability was being actively exploited.