Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v10 - Exploits Update (Fri Mar 05 2010)

OpenX Remote Code Execution Exploit

Exploits/Remote  [Linux]




• Fri Mar 05 2010
The vulnerability is caused due to the banner-edit.php script allowing the upload of files with arbitrary extensions to a folder inside the webroot. This can be exploited to e.g. execute arbitrary PHP code by uploading a specially crafted PHP script that contains the GIF magic number.

Exploits Vulnerabiltiy: CVE-2009-4098



< Back to Product Updates