CVE-2015-7369

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
14/10/2015
Last modified:
12/04/2025

Description

The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:* 3.2.1 (including)