Revive Adserver
revive-adserver
66 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (66)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn't properly escap...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to steal the session ID of a...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of pa...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user wi...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under s...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable to password-guessing attacks. An account lockdown feature was considere...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 3, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address. |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 3, 2017 N/A· v4 5.9 MEDIUM· v3 5.5 MEDIUM· v2 Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID. |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 3, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts. |
Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in...Show more |
Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the layerstyle parameter. |
Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct reques...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds plugin in Revive Adserver before 3.2.2 and CA Release Automation (formerly LISA Release Automatio...Show more |
The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors. |
Revive Adserver before 3.2.2 does not send the appropriate Cache-Control HTTP headers in responses for admin UI pages, which allows local users to obtain sensitive information via the web browser cache. |
Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked. |
Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authentication of users for requests that (1) perform certain plugin actions and possibly ca...Show more |
Cross-site scripting (XSS) vulnerability in the plugin upgrade form in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of an uploaded file containing errors. |