Описание
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. www/delivery/asyncspc.php was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually downloading a file from a trusted domain.
Ссылки
- PatchThird Party Advisory
- Permissions Required
- PatchVendor Advisory
- PatchThird Party Advisory
- Permissions Required
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.2.4 (включая)
Одно из
cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*
cpe:2.3:a:revive-adserver:revive_adserver:4.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.0054
Низкий
9 Critical
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-79
CWE-254
Связанные уязвимости
CVSS3: 9
github
больше 3 лет назад
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually downloading a file from a trusted domain.
EPSS
Процентиль: 67%
0.0054
Низкий
9 Critical
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-79
CWE-254