Products

Showing 3 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
revive-adserver vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Revive Adserver 5.4.1 Cross-Site Scripting via Banner Advanced Settings

Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a malicious link to the banner-advanced.php endpoint with XSS payloads in prepend and append parameters to execute arbitrary JavaScript when an admin views the page.

CWE-79Dec 17, 2025
CVSS5.1v4.0EPSS2.4%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

revive-adserver revive_adserver URL Redirection to Untrusted Site ('Open Redirect')

Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when delivering ads. However, third party click tracking via redirects is not a viable option anymore, leading to such open redirect functionality being removed and reclassified as a vulnerability.

CWE-601Jan 21, 20211 related artifact
CVSS6.1v3.1EPSS69.6%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

revive-adserver revive_adserver Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an http-only cookie as of v3.2.2. On older versions, however, under specific circumstances, it could be possible to steal the session identifier and gain access to the admin interface. The query string sent to the www/delivery/afr.php script was printe

CWE-79Feb 4, 20201 related artifact
CVSS6.1v3.1EPSS7.06%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX