CVE-2015-7365: XSS
Published Oct 14, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the plugin upgrade form in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of an uploaded file containing errors.
Affected Software
1 affected component
revive-adserver Revive Adserver<=3.2.1
Event History
Oct 14, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7365?
The severity of CVE-2015-7365 is considered to be medium due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-7365?
To fix CVE-2015-7365, upgrade Revive Adserver to version 3.2.2 or later.
3
What types of attacks can CVE-2015-7365 facilitate?
CVE-2015-7365 can facilitate cross-site scripting (XSS) attacks which allow attackers to inject malicious scripts into web pages.
4
Which versions of Revive Adserver are affected by CVE-2015-7365?
Revive Adserver versions before 3.2.2, specifically up to 3.2.1, are affected by CVE-2015-7365.
5
Can CVE-2015-7365 be exploited remotely?
Yes, CVE-2015-7365 can be exploited remotely by attackers through the plugin upgrade form.