VYPR
Unrated severityNVD Advisory· Published Oct 23, 2014· Updated May 6, 2026

CVE-2014-2230

CVE-2014-2230

Description

Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

Affected products

11
  • Openx/Openx11 versions
    cpe:2.3:a:openx:openx:*:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:openx:openx:*:*:*:*:*:*:*:*range: <=2.8.10
    • cpe:2.3:a:openx:openx:2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.6:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.7:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.8:*:*:*:*:*:*:*
    • cpe:2.3:a:openx:openx:2.8.9:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.