Vulnerabilities
Vulnerable Software
A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..
CVSS Score
6.1
EPSS Score
0.057
Published
2023-09-17
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.
CVSS Score
7.1
EPSS Score
0.005
Published
2021-09-23
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code.
CVSS Score
6.1
EPSS Score
0.008
Published
2021-03-25
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and pressing a certain key combination to execute injected JavaScript code.
CVSS Score
6.1
EPSS Score
0.008
Published
2021-03-25


Contact Us

Shodan ® - All rights reserved