PT-2017-10146 · Revive Adserver Team · Revive Adserver

Decidedlygray

·

Publicado

2017-03-28

·

Atualizado

2017-03-30

·

CVE-2016-9455

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 3.2.3
Description The issue affects the user interface of Revive Adserver, where several scripts are susceptible to Cross-Site Request Forgery (CSRF) attacks. The vulnerable scripts include www/admin/banner-acl.php, www/admin/banner-activate.php, www/admin/banner-advanced.php, www/admin/banner-modify.php, www/admin/banner-swf.php, www/admin/banner-zone.php, and www/admin/tracker-modify.php.
Recommendations For Revive Adserver versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable scripts until the update can be applied.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9455

Produtos afetados

Revive Adserver