CVE-2014-9407
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) delete data via a request to agency-delete.php, (2) tracker-delete.php, or (3) userlog-delete.php in admin/ or (4) unlink accounts via a request to admin-user-unlink.php. (5) advertiser-user-unlink.php, or (6) affiliate-user-unlink.php in admin/.
Diversas vulnerabilidades de CSRF en Revive Adserver anterior a 3.0.5 permite a atacantes remotos secuestrar la autenticación de los administradores para peticiones que (1) borren datos a través de una petición a agency-delete.php, (2) a tracker-delete.php o (3) a userlog-delete.php en admin/ o (4) desenlazar cuentas a través de peticiones a admin-user-unlink.php. (5) a advertiser-user-unlink.php o (6) affiliate-user-unlink.php en admin/.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-12-19 CVE Reserved
- 2014-12-19 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.revive-adserver.com/security/revive-sa-2014-001 | 2014-12-19 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Revive-adserver Search vendor "Revive-adserver" | Revive Adserver Search vendor "Revive-adserver" for product "Revive Adserver" | <= 3.0.4 Search vendor "Revive-adserver" for product "Revive Adserver" and version " <= 3.0.4" | - |
Affected
|