The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.
References
Configurations
Information
Published : 2015-10-14 12:59
Updated : 2018-10-09 12:58
NVD link : CVE-2015-7369
Mitre link : CVE-2015-7369
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
revive-adserver
- revive_adserver