Description
Cross-site scripting (XSS) vulnerability in lib/max/Admin/UI/Field/PublisherIdField.php in Revive Adserver before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via the refresh_page parameter to www/admin/report-generate.php.
Remediation
References
Related Vulnerabilities
Moodle Other Vulnerability (CVE-2004-2237)
Squid Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9749)
WordPress Plugin YITH WooCommerce Gift Cards Premium Unspecified Vulnerability (3.20.0)
osTicket Other Vulnerability (CVE-2005-1436)
WordPress Plugin FeedList 'handler_image.php' Cross-Site Scripting (2.61.01)