Description
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the banner related pages.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-0433 Vulnerability (CVE-2015-0433)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2017-5659)
WordPress Plugin Custom Permalinks SQL Injection (1.1)
WordPress Plugin Spam Free WordPress Security Bypass (1.9.2)
Oracle Database Server CVE-2014-6547 Vulnerability (CVE-2014-6547)