Vulnerabilities > Revive Adserver

DATE CVE VULNERABILITY TITLE RISK
2017-03-28 CVE-2016-9454 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
3.5
2017-03-28 CVE-2016-9130 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
3.5
2017-03-28 CVE-2016-9129 Information Exposure vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy.
network
low complexity
revive-adserver CWE-200
5.0
2017-03-28 CVE-2016-9128 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from reflected XSS.
3.5
2017-03-28 CVE-2016-9127 Cross-Site Request Forgery (CSRF) vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF).
6.8
2017-03-28 CVE-2016-9126 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from persistent XSS.
3.5
2017-03-28 CVE-2016-9125 Session Fixation vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication.
network
low complexity
revive-adserver CWE-384
7.5
2017-03-28 CVE-2016-9124 Improper Authentication vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.
network
low complexity
revive-adserver CWE-287
5.0
2017-03-03 CVE-2017-5833 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
4.3
2017-03-03 CVE-2017-5832 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.
3.5