Description
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the banner related pages.
Remediation
References
Related Vulnerabilities
Internet Information Services CVE-2006-6578 Vulnerability (CVE-2006-6578)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-5096)
WordPress Plugin Count per Day Cross-Site Request Forgery (3.2.5)
Drupal Improper Access Control Vulnerability (CVE-2016-3165)
WordPress Plugin JM Twitter Cards Information Disclosure (6.1)