Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.
CVSS Information
N/A
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
revive adserver 代码注入漏洞
Vulnerability Description
revive adserver是revive团队开源的一个广告服务器软件。 revive adserver 6.0.6及之前版本存在代码注入漏洞,该漏洞源于在保存投放限制时缺少用户输入验证,可能导致低权限用户使用logical参数将恶意PHP代码注入数据库中的compiledlimitations字段,并在广告投放期间执行。
CVSS Information
N/A
Vulnerability Type
N/A