Revive-adserver

Revive Adserver

67 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.63%
  • Veröffentlicht 03.04.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:22

A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in user to type the current password in order to change...

Exploit
  • EPSS 7.06%
  • Veröffentlicht 04.02.2020 20:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:19

A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an...

Exploit
  • EPSS 1.58%
  • Veröffentlicht 28.05.2019 19:29:06
  • Zuletzt bearbeitet 21.11.2024 04:44:56

Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality. In lib/OA/Dal/PasswordRecovery.php, ...

Exploit
  • EPSS 1.68%
  • Veröffentlicht 06.05.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:44:55

A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials o...

  • EPSS 1.64%
  • Veröffentlicht 28.03.2017 02:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other parameters. It has to be noted that the window for such ...

  • EPSS 1.37%
  • Veröffentlicht 28.03.2017 02:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when creating users on a Revive Adserver instance. Especially, control characters were not filtered, allowing apparently identical use...

  • EPSS 2.1%
  • Veröffentlicht 28.03.2017 02:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's ...

  • EPSS 0.87%
  • Veröffentlicht 28.03.2017 02:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn't properly escaped when displayed in the campa...

  • EPSS 2.23%
  • Veröffentlicht 28.03.2017 02:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable to password-guessing attacks. An account lockdown feature was considered, but rejected to avoid intro...

  • EPSS 2.66%
  • Veröffentlicht 28.03.2017 02:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could ...