Vulnerabilities > Revive Adserver
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-04-03 | CVE-2020-8142 | Incorrect Authorization vulnerability in Revive-Adserver Revive Adserver A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. | 6.8 |
2020-02-04 | CVE-2020-8115 | Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. | 6.1 |
2019-05-28 | CVE-2019-5440 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Revive-Adserver Revive Adserver Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality. | 8.1 |
2019-05-06 | CVE-2019-5433 | Open Redirect vulnerability in Revive-Adserver Revive Adserver A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks. | 5.4 |
2017-03-28 | CVE-2016-9472 | Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. | 5.4 |
2017-03-28 | CVE-2016-9471 | Unspecified vulnerability in Revive-Adserver Revive Adserver Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. | 3.1 |
2017-03-28 | CVE-2016-9470 | 7PK - Security Features vulnerability in Revive-Adserver Revive Adserver Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. | 9.0 |
2017-03-28 | CVE-2016-9457 | Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver Revive Adserver before 3.2.3 suffers from Reflected XSS. | 5.4 |
2017-03-28 | CVE-2016-9456 | Cross-Site Request Forgery (CSRF) vulnerability in Revive-Adserver Revive Adserver Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). | 8.8 |
2017-03-28 | CVE-2016-9455 | Cross-Site Request Forgery (CSRF) vulnerability in Revive-Adserver Revive Adserver Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). | 8.8 |