← Vulnerability feed

Vulnerability record · CVE-2013-7149 · published 28 December 2013

CVE-2013-7149: Openx sql injection vulnerability

Openx · Openx

SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.

7.5 CVSS 2.0 High EPSS 2.0% · top 19.9% CWE-89 · SQL injection
7.5CVSS 2.0 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-7149 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-4211OpenX Ad Server backdoor in flowplayer library allows PHP code executionOpenX Ad Server 2.8.10 ships a backdoored flowplayer-3.1.1.min.js library that permits remote arbitrary PHP code execution. The flaw is a code inject…EPSS 71%analysed9.8CVE-2016-9124Revive-adserver revive adserver improper restriction of authentication attempts vulnerabilityRevive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable …EPSS 2.2%9.8CVE-2016-9125Revive-adserver revive adserver vulnerabilityRevive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not inva…EPSS 2.7%9.8CVE-2017-5830Revive-adserver revive adserver deserialization of untrusted data vulnerabilityRevive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.EPSS 3.3%9.0CVE-2016-9470Revive-adserver revive adserver cross-site scripting vulnerabilityRevive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected F…EPSS 2.1%8.8CVE-2026-50741Revive-adserver revive adserver code injection vulnerabilityBypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sen…EPSS 4.9%8.8CVE-2025-48986Revive-adserver revive adserver improper access control vulnerabilityAuthorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and po…EPSS 0.62%8.8CVE-2025-52664Revive-adserver revive adserver sql injection vulnerabilitySQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in use…EPSS 0.92%

Source: NIST National Vulnerability Database (record CVE-2013-7149), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.