Reflected File Download Vulnerability in Revive Adserver by Revive Adserver
CVE-2016-9470

9CRITICAL

What is CVE-2016-9470?

Revive Adserver prior to versions 3.2.5 and 4.0.0 is susceptible to a Reflected File Download (RFD) attack. This vulnerability in the www/delivery/asyncspc.php file allows attackers to exploit the web application. By using this vulnerability, attackers can trick users into downloading harmful files disguised as legitimate ones. When successful, this can lead to unauthorized control over the victim's system, as the file is downloaded from a trusted source, making it difficult for users to detect the threat.

Affected Version(s)

Revive Adserver All before 3.2.5 and 4.0.0 Revive Adserver All versions before 3.2.5 and 4.0.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.