Revive-adserver

Revive Adserver

67 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.17%
  • Veröffentlicht 03.03.2017 15:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.

  • EPSS 1.68%
  • Veröffentlicht 03.03.2017 15:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

  • EPSS 1.95%
  • Veröffentlicht 14.10.2015 19:59:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in a banner.

  • EPSS 3.07%
  • Veröffentlicht 14.10.2015 19:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the layerstyle parameter.

  • EPSS 2.59%
  • Veröffentlicht 14.10.2015 19:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct request.

  • EPSS 2.24%
  • Veröffentlicht 14.10.2015 19:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple cross-site scripting (XSS) vulnerabilities in open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds plugin in Revive Adserver before 3.2.2 and CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5...

  • EPSS 3.25%
  • Veröffentlicht 14.10.2015 19:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.

  • EPSS 0.54%
  • Veröffentlicht 14.10.2015 19:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Revive Adserver before 3.2.2 does not send the appropriate Cache-Control HTTP headers in responses for admin UI pages, which allows local users to obtain sensitive information via the web browser cache.

  • EPSS 2.54%
  • Veröffentlicht 14.10.2015 19:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked.

  • EPSS 1.11%
  • Veröffentlicht 14.10.2015 19:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authentication of users for requests that (1) perform certain plugin actions and possibly cause a denial of service (disab...