NVD

Id
84037  
Name
CVE-2016-9471  
Description
Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren"t properly sanitised when creating users on a Revive Adserver instance. Especially, control characters were not filtered, allowing apparently identical usernames to co-exist in the system, due to the fact that such characters are normally ignored when an HTML page is displayed in a browser. The issue could have therefore been exploited for user spoofing, although elevated privileges are required to create users within Revive Adserver.  
Reject
 
CVSS Version
2  
CVSS Score
2.1  
Severity
Low  
CVSS Base Score
2.1  
CVSS Impact Subscore
2.9  
CVSS Exploit Subscore
3.9  
CVSS Vector
(AV:N/AC:H/Au:S/C:N/I:P/A:N)  
Pub Date
2017-03-29  
Published
2017-03-27  
Modified Date
2017-03-29  
Seq
2016-9471  

Actions