Unrated severityNVD Advisory· Published Jul 29, 2013· Updated Apr 29, 2026
CVE-2013-3515
CVE-2013-3515
Description
Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) package parameter to www/admin/plugin-index.php or the (2) group parameter to www/admin/plugin-settings.php.
Affected products
23cpe:2.3:a:openx:openx:2.6.0:*:*:*:*:*:*:*+ 22 more
- cpe:2.3:a:openx:openx:2.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.7.29:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.8:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.8.5:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:*:*:*:*:*:*:*:*range: <=2.8.10
- cpe:2.3:a:openx:openx:2.4:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.4.9:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.4.11:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- svn.openx.org/openx/trunk/www/admin/plugin-index.phpnvdPatch
- svn.openx.org/openx/trunk/www/admin/plugin-settings.phpnvdPatch
- seclists.org/bugtraq/2013/Jul/27nvdExploit
- www.exploit-db.com/exploits/26624nvdExploit
- www.htbridge.com/advisory/HTB23155nvdExploit
- osvdb.org/94774nvd
- osvdb.org/94775nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/85411nvd
- www.htbridge.com/advisory/HTB23155-openx-changeset-82710.diffnvd
News mentions
0No linked articles in our index yet.