Show filters
545 Total Results
Displaying 381-390 of 545
Sort by:
Attacker Value
Unknown
CVE-2015-7369
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-7371
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct request.
0
Attacker Value
Unknown
CVE-2015-7366
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authentication of users for requests that (1) perform certain plugin actions and possibly cause a denial of service (disabled core plugins) via unknown vectors or (2) change the contact name and language or possibly have unspecified other impact via a crafted POST request to an account-user-*.php script.
0
Attacker Value
Unknown
CVE-2015-7373
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in a banner.
0
Attacker Value
Unknown
CVE-2015-7368
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
Revive Adserver before 3.2.2 does not send the appropriate Cache-Control HTTP headers in responses for admin UI pages, which allows local users to obtain sensitive information via the web browser cache.
0
Attacker Value
Unknown
CVE-2015-7364
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
The HTML_Quickform library, as used in Revive Adserver before 3.2.2, allows remote attackers to bypass the CSRF protection mechanism via an empty token.
0
Attacker Value
Unknown
CVE-2015-7370
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds plugin in Revive Adserver before 3.2.2 and CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026, allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) data-file parameter.
0
Attacker Value
Unknown
CVE-2015-7601
Disclosure Date: September 29, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.
0
Attacker Value
Unknown
CVE-2014-3148
Disclosure Date: August 31, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in libahttp/err.c in OkCupid OKWS (OK Web Server) allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to a non-existent page, which is not properly handled in a 404 error page.
0
Attacker Value
Unknown
CVE-2015-4108
Disclosure Date: June 10, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to admin_lua_script.html or (2) add a domain administrator via a crafted request to admin_addadmin.html.
0