Vulnerabilities > Revive Adserver

DATE CVE VULNERABILITY TITLE RISK
2017-03-03 CVE-2017-5831 Session Fixation vulnerability in Revive-Adserver Revive Adserver
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
network
high complexity
revive-adserver CWE-384
5.9
2017-03-03 CVE-2017-5830 Deserialization of Untrusted Data vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.
network
low complexity
revive-adserver CWE-502
critical
9.8