Description
Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to steal the session ID of an authenticated user, by tricking them into visiting a specifically crafted URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin Appointment Hour Booking-WordPress Booking Cross-Site Scripting (1.1.44)
WordPress Plugin Gallery-Video Gallery and Youtube Gallery SQL Injection (2.0.9)
WordPress Plugin Commentator Cross-Site Scripting (2.5.2)
WordPress Plugin Inline Related Posts Multiple Cross-Site Scripting Vulnerabilities (3.0.4)