SQL Injection Vulnerability in Revive Adserver by Revive Adserver
CVE-2026-34915

6.1MEDIUM

Key Information:

Vendor

Revive

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-34915?

A vulnerability in the zone-include.php script of Revive Adserver versions 6.0.6 and earlier allows low-privileged users to exploit the clientid parameter, potentially leading to blind SQL injection attacks. This occurs due to a lack of proper input sanitization, which has now been addressed to ensure all parameters processed by the script are thoroughly validated, enhancing overall security.

Affected Version(s)

Adserver 0 <= 6.0.6

References

CVSS V3.0

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kaushalendra Dubey (titanrain)
.