Vulnerability record · CVE-2013-4211 · published 14 February 2020
CVE-2013-4211: OpenX Ad Server backdoor in flowplayer library allows PHP code execution
Openx · Openx
OpenX Ad Server 2.8.10 ships a backdoored flowplayer-3.1.1.min.js library that permits remote arbitrary PHP code execution. The flaw is a code injection (CWE-94) reachable over the network without authentication, and it carries a critical CVSS 3.1 score of 9.8. Because the malicious code is embedded in a distributed library file, any deployment of the affected version is exposed.
Description
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, public exploit code and a very high EPSS score make this an urgent risk for any host still running the affected version.
What it is
OpenX Ad Server 2.8.10 ships a backdoored flowplayer-3.1.1.min.js library that permits remote arbitrary PHP code execution. The flaw is a code injection (CWE-94) reachable over the network without authentication, and it carries a critical CVSS 3.1 score of 9.8. Because the malicious code is embedded in a distributed library file, any deployment of the affected version is exposed.
Impact
An unauthenticated remote attacker can execute arbitrary PHP code on the server, leading to full compromise of the web application and its data. Given the CVSS impact ratings of high for confidentiality, integrity and availability, the attacker can read, modify or destroy anything the web server process can reach.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), per the CVSS vector. The backdoor resides in the flowplayer-3.1.1.min.js library bundled with OpenX Ad Server 2.8.10, so exploitation targets the server hosting that file.
Exploitation
Public exploit code exists, as indicated by Exploit and Exploit-DB tags in the references, and EPSS gives a 30-day probability of 0.70653 (99.36th percentile). CISA KEV does not list this CVE, so there is no confirmed in-the-wild exploitation record from that source.
What to do
- Upgrade or replace OpenX Ad Server 2.8.10 with a supported, non-backdoored release; if no fixed version exists, retire the product.
- Remove or replace the bundled flowplayer-3.1.1.min.js file and verify the integrity of all third-party JavaScript libraries against known-good hashes.
- Isolate any remaining OpenX instance behind a reverse proxy or WAF and restrict outbound network access from the web server.
- Audit the web server for unexpected PHP files, webshells and modified library files, and restore from a trusted baseline.
- Rotate credentials and secrets accessible to the OpenX application and its database.
Detection
- Search the web root for flowplayer-3.1.1.min.js and compare its hash against the official upstream release.
- Monitor web server logs for requests to flowplayer-3.1.1.min.js followed by unusual POST or GET parameters that could trigger PHP execution.
- Hunt for newly created or modified PHP files in web-accessible directories, especially webshell-like patterns.
- Alert on outbound connections from the OpenX host to unfamiliar IPs or domains, which may indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.exploit-db.com/exploits/27529 | ExploitThird Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2013/08/07/2 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/61650 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/86259 | Third Party AdvisoryVDB Entry |
| https://packetstormsecurity.com/files/cve/CVE-2013-4211 | ExploitThird Party AdvisoryVDB Entry |
| http://www.exploit-db.com/exploits/27529 | ExploitThird Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2013/08/07/2 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/61650 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/86259 | Third Party AdvisoryVDB Entry |
| https://packetstormsecurity.com/files/cve/CVE-2013-4211 | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2013-4211 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4211), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.