Vulnerabilities > Revive Adserver > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-04 CVE-2020-8115 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi.
network
low complexity
revive-adserver CWE-79
6.1
2019-05-06 CVE-2019-5433 Open Redirect vulnerability in Revive-Adserver Revive Adserver
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks.
network
low complexity
revive-adserver CWE-601
5.4
2017-03-28 CVE-2016-9472 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9457 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9454 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9130 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9129 Information Exposure vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy.
network
low complexity
revive-adserver CWE-200
5.3
2017-03-28 CVE-2016-9128 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9126 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-03 CVE-2017-5833 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
low complexity
revive-adserver CWE-79
6.1