Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Krzysztof K. Wasielewski

#20486of 53,633
12.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2015-7534
5.0
2015-10-14
Revive Adserver Team · Revive Adserver · CVE-2015-7371
**Name of the Vulnerable Software and Affected Versions** Revive Adserver versions prior to 3.2.2 **Description** The issue allows remote attackers to cause a denial of service, potentially leading to resource consumption, by directly requesting a specific endpoint. **Recommendations** For versions prior to 3.2.2, update to version 3.2.2 or later to resolve the issue.
PT-2015-7535
7.5
2015-10-14
Revive Adserver · Revive Adserver · CVE-2015-7372
**Name of the Vulnerable Software and Affected Versions** Revive Adserver versions prior to 3.2.2 **Description** A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the `layerstyle` parameter. **Recommendations** For versions prior to 3.2.2, update to version 3.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the `al.php` file in the `delivery-dev` directory until a patch is applied. Avoid using the `layerstyle` parameter in the affected endpoint until the issue is resolved.