NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83993 | CVE-2016-9127 | Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of password recovery emails to the registered users, especially in conjunction with a bug that caused recovery emails to be sent to all the users at once. Both issues have been fixed. | 2 | 6.8 | Medium | 2017-03-29 | 2017-03-29 | View | |
83994 | CVE-2016-9128 | Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to steal the session ID of an authenticated user, by tricking them into visiting a specifically crafted URL. | 2 | 3.5 | Low | 2017-03-29 | 2017-03-29 | View | |
83995 | CVE-2016-9129 | Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username. | 2 | 5 | Medium | 2017-03-29 | 2017-03-29 | View | |
83996 | CVE-2016-9130 | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn"t properly escaped when displayed in the campaign-zone.php script. | 2 | 3.5 | Low | 2017-03-29 | 2017-03-29 | View | |
84021 | CVE-2016-9454 | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn"t properly escaped when displayed in most of the banner related pages. | 2 | 3.5 | Low | 2017-03-29 | 2017-03-29 | View |
Page 15792 of 17672, showing 5 records out of 88360 total, starting on record 78956, ending on 78960