OpenX versions 2.4.9 and below and versions 2.6.3 and below suffer from cross site scripting, SQL injection, and directory traversal vulnerabilities.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74491/OPENX-SA-2009-001.txt
Source: https://packetstormsecurity.com/files/74491/OpenX-Security-Advisory-XSS-SQL-Injection-Directory-Traversal.html

