Loading
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.
Use CWE-89, Openx vendor hub and Openx product page to widen CVE-2013-7149 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2013-4211, CVE-2012-4990 and CVE-2009-4830 for nearby disclosures in the same product family.