Revive-adserver

Revive Adserver

60 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 22:44:58
  • Zuletzt bearbeitet 27.12.2025 17:15:44

Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a malicious link to the banner-advanced.php endpoint with XSS payload...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 02.12.2025 20:19:57

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 25.11.2025 18:56:45

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 25.11.2025 18:57:29

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 26.11.2025 16:56:10

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 05.12.2025 20:17:35

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 02.12.2025 20:05:41

Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 02.12.2025 20:17:35

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

Exploit
  • EPSS 0.01%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 02.12.2025 20:19:15

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 02.12.2025 20:24:38

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.