Vulnerabilities > Revive Adserver

DATE CVE VULNERABILITY TITLE RISK
2017-03-28 CVE-2016-9454 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9130 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9129 Information Exposure vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy.
network
low complexity
revive-adserver CWE-200
5.3
2017-03-28 CVE-2016-9128 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9127 Cross-Site Request Forgery (CSRF) vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF).
network
low complexity
revive-adserver CWE-352
8.8
2017-03-28 CVE-2016-9126 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9125 Session Fixation vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication.
network
low complexity
revive-adserver CWE-384
critical
9.8
2017-03-28 CVE-2016-9124 Improper Authentication vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.
network
low complexity
revive-adserver CWE-287
critical
9.8
2017-03-03 CVE-2017-5833 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
low complexity
revive-adserver CWE-79
6.1
2017-03-03 CVE-2017-5832 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.
network
low complexity
revive-adserver CWE-79
5.4