Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Smit B. Shah

#17818de 53,638
15.1CVSS total
Vulnerabilidades · 2
Média
1
Crítica
1
PT-2017-9961
9.8
2017-03-28
Revive Adserver · Revive Adserver · CVE-2016-9124
**Name of the Vulnerable Software and Affected Versions** Revive Adserver versions prior to 3.2.3 **Description** The issue allows for password-guessing attacks due to improper restriction of excessive authentication attempts on the login page. A countermeasure has been introduced, including a random delay in case of password failures and a system to discourage parallel brute forcing, aiming to allow valid users to log in even during an attack. **Recommendations** For versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue.
PT-2017-9966
5.3
2017-03-28
Revive Adserver · Revive Adserver · CVE-2016-9129
**Name of the Vulnerable Software and Affected Versions** Revive Adserver versions prior to 3.2.3 **Description** The issue allows an attacker to determine whether an email address is associated with one or more user accounts by analyzing the message from the password recovery system. However, this information cannot be used directly to log in to the system, as a username is required. **Recommendations** For versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue.