CVE-2013-7149
CVE-2013-7149 is a high-severity vulnerability in Openx with a CVSS 2.0 base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-89.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 2% (80th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-89
- Affected product: Openx
- Published:
- Last modified:
Description
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.
Frequently asked questions
- What is CVE-2013-7149?
- SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.
- How severe is CVE-2013-7149?
- CVE-2013-7149 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2013-7149 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (80th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2013-7149?
- CVE-2013-7149 primarily affects Openx. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2013-7149?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2013-7149 published?
- CVE-2013-7149 was published on 2013-12-28 and last updated on 2026-06-17.
References
- http://www.kreativrauschen.com/blog/2013/12/18/zero-day-vulnerability-in-openx-source-2-8-11-and-revive-adserver-3-0-1/
- http://www.revive-adserver.com/security/REVIVE-SA-2013-001/
- http://www.securityfocus.com/archive/1/530471/30/0/threaded
Affected products (4)
- cpe:2.3:a:openx:openx:*:*:*:*:*:*:*:*
- cpe:2.3:a:openx:openx:2.8.10:*:*:*:*:*:*:*
- cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*
- cpe:2.3:a:revive-adserver:revive_adserver:3.0.0:*:*:*:*:*:*:*
More vulnerabilities in Openx
- CVE-2013-4211 — Critical (CVSS 9.8): A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library,…
- CVE-2012-4990 — High (CVSS 7.5): SQL injection vulnerability in admin/campaign-zone-link.php in OpenX 2.8.10 before revision 81823 allows remote…
- CVE-2009-4830 — High (CVSS 7.5): Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access…
- CVE-2008-6163 — High (CVSS 7.5): SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL…
- CVE-2009-0291 — High (CVSS 7.5): Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary…
- CVE-2013-7376 — Medium (CVSS 6.8): Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow…
Other CWE-89 (SQL Injection) vulnerabilities
- CVE-2026-74820 — Critical (CVSS 10.0): ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This…
- CVE-2026-20030 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team…
- CVE-2026-72811 — Critical (CVSS 10.0): SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query…
- CVE-2026-72851 — Critical (CVSS 10.0): Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with…
- CVE-2026-72899 — Critical (CVSS 10.0): Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that…
- CVE-2026-72898 — Critical (CVSS 10.0): Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint…