Loading
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.
Use CWE-20, Openx vendor hub and Openx product page to widen CVE-2009-4098 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2013-4211, CVE-2013-7149 and CVE-2012-4990 for nearby disclosures in the same product family.