CORE IMPACT v10 - Exploits Update (Fri Mar 05 2010)
OpenX Remote Code Execution Exploit
Exploits/Remote [Linux]
Fri Mar 05 2010
The vulnerability is caused due to the banner-edit.php script allowing the upload of files with arbitrary extensions to a folder inside the webroot. This can be exploited to e.g. execute arbitrary PHP code by uploading a specially crafted PHP script that contains the GIF magic number.
Exploits Vulnerabiltiy: CVE-2009-4098











