CVE-2014-2230
Last modified
CVE-2014-2230 is a vulnerability of currently unknown severity. Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.. EPSS estimates a 1.97% chance of exploitation in the next 30 days.
Description
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openx | Openx | <= 2.8.10 |
| Openx | Openx | 2.8 |
| Openx | Openx | 2.8.1 |
| Openx | Openx | 2.8.2 |
| Openx | Openx | 2.8.3 |
| Openx | Openx | 2.8.4 |
| Openx | Openx | 2.8.5 |
| Openx | Openx | 2.8.6 |
| Openx | Openx | 2.8.7 |
| Openx | Openx | 2.8.8 |
| Openx | Openx | 2.8.9 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2230?
How severe is CVE-2014-2230?
How do I fix CVE-2014-2230?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-2223Unrestricted file upload vulnerability in plog-admin/plog-up…
- CVE-2014-2224Plogger 1.0 RC1 and earlier, when the Lucid theme is used, d…
- CVE-2014-2225Multiple cross-site request forgery (CSRF) vulnerabilities i…8.8
- CVE-2014-2226Ubiquiti UniFi Controller before 3.2.1 logs the administrati…
- CVE-2014-2227The default Flash cross-domain policy (crossdomain.xml) in U…
- CVE-2014-2228The XStream extension in HP Fortify SCA before 2.2 RC3 allow…9.8
- CVE-2014-2231Cross-site scripting (XSS) vulnerability in the API in synet…
- CVE-2014-2232Absolute path traversal vulnerability in the MapAPI in Infow…
- CVE-2014-2233Server-side request forgery (SSRF) vulnerability in the MapA…
- CVE-2014-2234A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and e…
- CVE-2014-2235Cross-site scripting (XSS) vulnerability in Askbot before 0.…
- CVE-2014-2236Multiple cross-site scripting (XSS) vulnerabilities in Askbo…
Are you affected by CVE-2014-2230?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
