CVE-2013-7149

high
Published 2013-12-28 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.revive-adserver.com/security/REVIVE-SA-2013-001/

Application impact

VendorProductVersionsFixed
openxopenx{"endIncluding":"2.8.11"}
openxopenx2.8.10
revive-adserverrevive_adserver{"endIncluding":"3.0.1"}
revive-adserverrevive_adserver3.0.0

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.