Computer Security
[EN] securityvulns.ru no-pyccku


CVECVE-2015-7370
StatusCandidate
DescriptionMultiple cross-site scripting (XSS) vulnerabilities in open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds plugin in Revive Adserver before 3.2.2, allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) data-file parameter.
Severity
Medium
CVSS score4,3
CVSS vector(AV:N/AC:M/Au:N/C:N/I:P/A:N)
PhaseAssigned (25.09.2015)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7370
ReferencesBUGTRAQ : 20151007 [REVIVE-SA-2015-001] Revive Adserver - Multiple vulnerabilities
 FULLDISC : 20151008 [REVIVE-SA-2015-001] Revive Adserver - Multiple vulnerabilities
 MISC : http://packetstormsecurity.com/files/133893/Revive...
 CONFIRM : http://www.revive-adserver.com/security/revive-sa-...
SecurityVulns:Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod