Vulnerabilities > Revive SAS

DATE CVE VULNERABILITY TITLE RISK
2019-05-06 CVE-2019-5434 Deserialization of Untrusted Data vulnerability in Revive-Sas Revive Adserver
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method.
network
low complexity
revive-sas CWE-502
critical
9.8