CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
95946 | CVE-2016-9126 | Candidate | Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user with enough privileges to create other users could exploit the vulnerability to access the administrator account. | Assigned (20161031) | None (candidate not yet proposed) | View | |
95947 | CVE-2016-9127 | Candidate | Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of password recovery emails to the registered users, especially in conjunction with a bug that caused recovery emails to be sent to all the users at once. Both issues have been fixed. | Assigned (20161031) | None (candidate not yet proposed) | View | |
95948 | CVE-2016-9128 | Candidate | Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to steal the session ID of an authenticated user, by tricking them into visiting a specifically crafted URL. | Assigned (20161031) | None (candidate not yet proposed) | View | |
95949 | CVE-2016-9129 | Candidate | Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username. | Assigned (20161031) | None (candidate not yet proposed) | View | |
95950 | CVE-2016-9130 | Candidate | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn"t properly escaped when displayed in the campaign-zone.php script. | Assigned (20161031) | None (candidate not yet proposed) | View |
Page 19190 of 20943, showing 5 records out of 104715 total, starting on record 95946, ending on 95950