Cross Site Request Forgery of the OpenX AdServer
31.07.11 (Allgemein)
Last week a possible Cross Site Request Forgery of the OpenX AdServer was found, please see: http://www.exploit-db.com/exploits/17571/ The attached document contains a patchset I’ve just prepared to fix any of the “?????-delete.php” CSRFs – it is based on OpenX 2.8.7 and could be applied using the “patch” command. NO WARRANTYTHE PATCHSET IS DISTRIBUTED IN THE HOPE [...]