PT-2015-7529 · Revive Adserver · Revive Adserver

N B Sri Harsha

·

Publicado

2015-10-14

·

Atualizado

2018-10-09

·

CVE-2015-7366

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 3.2.2
Description The issue allows remote attackers to hijack user authentication for certain requests, potentially causing a denial of service or modifying user account details. This can be achieved via crafted POST requests to specific scripts, such as account-user-*.php, allowing attackers to perform actions like changing the contact name and language.
Recommendations For versions prior to 3.2.2, update to version 3.2.2 or later to resolve the issue.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7366

Produtos afetados

Revive Adserver