Files
CVEs-PoC/2016/CVE-2016-9128.md
2025-09-29 21:09:30 +02:00

992 B

CVE-2016-9128

Description

Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to steal the session ID of an authenticated user, by tricking them into visiting a specifically crafted URL.

POC

Reference

Github

No PoCs found on GitHub currently.