Vulnerabilities > Revive Adserver > Revive Adserver > 3.2.4

DATE CVE VULNERABILITY TITLE RISK
2020-04-03 CVE-2020-8142 Incorrect Authorization vulnerability in Revive-Adserver Revive Adserver
A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144.
local
low complexity
revive-adserver CWE-863
4.6
2020-02-04 CVE-2020-8115 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi.
4.3
2019-05-28 CVE-2019-5440 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Revive-Adserver Revive Adserver
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality.
6.8
2019-05-06 CVE-2019-5433 Open Redirect vulnerability in Revive-Adserver Revive Adserver
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks.
5.8
2017-03-28 CVE-2016-9472 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS.
3.5
2017-03-28 CVE-2016-9471 Unspecified vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection.
network
high complexity
revive-adserver
2.1
2017-03-28 CVE-2016-9470 7PK - Security Features vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download.
network
revive-adserver CWE-254
critical
9.3
2017-03-03 CVE-2017-5833 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
4.3
2017-03-03 CVE-2017-5832 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.
3.5
2017-03-03 CVE-2017-5831 Session Fixation vulnerability in Revive-Adserver Revive Adserver
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
network
low complexity
revive-adserver CWE-384
5.5