Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Althaf Shajahan

#22510of 54,922
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-61656
5.4
2026-07-20
Revive · Andserver · CVE-2026-50743
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.
PT-2026-52650
5.4
2026-06-26
Unknown · Revive Adserver · CVE-2026-50742
**Name of the Vulnerable Software and Affected Versions** Revive Adserver version 6.0.7 **Description** Stored Cross-Site Scripting (XSS) occurs in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools. The issue arises when entity names are displayed without proper escaping during the detection of inconsistencies. This allows a stored script to be executed when an administrator utilizes these maintenance tools, although the exact execution is not fully controllable by the attacker. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.