Loading
Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) package parameter to www/admin/plugin-index.php or the (2) group parameter to www/admin/plugin-settings.php.
Use CWE-79, Openx vendor hub and Openx product page to widen CVE-2013-3515 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2013-4211, CVE-2013-7149 and CVE-2012-4990 for nearby disclosures in the same product family.