CVE-2016-9472
Estado: ModificadaMedia (5.4)—
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other parameters. It has to be noted that the window for such attack vectors to be possible is extremely narrow and it is very unlikely that such an attack could be actually effective.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.64%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
- CWE-79
Referencias
- https://github.com/revive-adserver/revive-adserver/commit/14ff73f0
- https://github.com/revive-adserver/revive-adserver/commit/fcf72c8a
- https://hackerone.com/reports/170156
- https://www.revive-adserver.com/security/revive-sa-2016-002/
- https://github.com/revive-adserver/revive-adserver/commit/14ff73f0
- https://github.com/revive-adserver/revive-adserver/commit/fcf72c8a
- https://hackerone.com/reports/170156
- https://www.revive-adserver.com/security/revive-sa-2016-002/
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-9472",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Revive Adserver All versions before 3.2.5 and 4.0.0",
"versions": [
{
"status": "affected",
"version": "Revive Adserver All versions before 3.2.5 and 4.0.0"
}
]
}
]
}
],
"published": "2017-03-28T02:59:01.387",
"references": [
{
"url": "https://github.com/revive-adserver/revive-adserver/commit/14ff73f0",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://github.com/revive-adserver/revive-adserver/commit/fcf72c8a",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://hackerone.com/reports/170156",
"tags": [
"Permissions Required"
],
"source": "support@hackerone.com"
},
{
"url": "https://www.revive-adserver.com/security/revive-sa-2016-002/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://github.com/revive-adserver/revive-adserver/commit/14ff73f0",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/revive-adserver/revive-adserver/commit/fcf72c8a",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hackerone.com/reports/170156",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.revive-adserver.com/security/revive-sa-2016-002/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "support@hackerone.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other parameters. It has to be noted that the window for such attack vectors to be possible is extremely narrow and it is very unlikely that such an attack could be actually effective."
},
{
"lang": "es",
"value": "Revive Adserver en versiones anteriores a 3.2.5 y 4.0.0 sufren de XSS reflejado. Los scripts del instalador web de Revive Adserver eran vulnerables a un ataque XSS reflejado a través de dbHost, dbUser y posiblemente otros parámetros. Debe tenerse en cuenta que la ventana para que tales vectores de ataque sean posibles es extremadamente estrecha y es muy improbable que tal ataque pueda ser efectivamente efectivo."
}
],
"lastModified": "2026-06-17T00:56:08.257",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34AB418F-BAAC-4C3D-9565-14A5E4F48970",
"versionEndIncluding": "3.2.4"
},
{
"criteria": "cpe:2.3:a:revive-adserver:revive_adserver:4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D6CDCD2-5AA9-4CBB-9AB7-3CD6D2A5F23E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "support@hackerone.com"
}