FreshPorts - VuXML
This page displays vulnerability information about FreeBSD Ports.
The last vuln.xml file processed by FreshPorts is:
List all Vulnerabilities, by package
List all Vulnerabilities, by date
These are the vulnerabilities relating to the commit you have selected:
|3e33a0bb-6b2f-11e3-b042-20cf30e32f6d||OpenX -- SQL injection vulnerability|
An SQL-injection vulnerability was recently discovered and reported
to the Revive Adserver team by Florian Sander. The vulnerability is
known to be already exploited to gain unauthorised access to the
application using brute force mechanisms, however other kind of
attacks might be possible and/or already in use. The risk is rated
to be critical as the most common end goal of the attackers is to
spread malware to the visitors of all the websites and ad networks
that the ad server is being used on.
The vulnerability is also present and exploitable in OpenX Source
2.8.11 and earlier versions, potentially back to phpAdsNew 2.0.x.
|dee44ba9-08ab-11e2-a044-d0df9acfd7e5||OpenX -- SQL injection vulnerability|
A vulnerability has been discovered in OpenX, which can be
exploited by malicious people to conduct SQL injection
Input passed via the "xajaxargs" parameter to
www/admin/updates-history.php (when "xajax" is set to
"expandOSURow") is not properly sanitised in e.g. the
(lib/OA/Upgrade/DB_UpgradeAuditor.php) before being used in SQL
queries. This can be exploited to manipulate SQL queries by
injecting arbitrary SQL code.
The vulnerability is confirmed in version 2.8.9. Prior versions
may also be affected.