Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.
| Software | From | Fixed in |
|---|---|---|
| openx / openx | - | 2.8.1.x |
| openx / openx | 2.8 | 2.8.x |
| openx / openx | 2.4 | 2.4.x |
| openx / openx | 2.6.3 | 2.6.3.x |
| openx / openx | 2.6.1 | 2.6.1.x |