Security researchers from High-Tech Bridge have identified an SQL Injection vulnerability in the Orbit Open Ad Server, a popular open-source ads server, that could have been leveraged to compromise websites running vulnerable installations.
The issue was discovered in mid-March. OrbitScripts LLC fixed the vulnerability shortly after being notified. The security hole has been addressed with the release of Orbit Open Ad Server 1.1.1.
Version 1.1.0 and probably prior variants are impacted, whi…