Description
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually downloading a file from a trusted domain.
Remediation
References
Related Vulnerabilities
ownCloud CVE-2017-9340 Vulnerability (CVE-2017-9340)
WordPress Plugin TheCartPress eCommerce Shopping Cart Multiple Vulnerabilities (1.5.3.6)
MyBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-41362)
WordPress Plugin Flat Preloader Cross-Site Request Forgery (1.5.3)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5204)