Description
Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct request.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Calls to Action Multiple Cross-Site Scripting Vulnerabilities (2.5.0)
WordPress Plugin Ultimate WordPress Auction Cross-Site Request Forgery (1.0.0)
WordPress Plugin Process Steps Template Designer Cross-Site Request Forgery (1.2.1)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1607)