Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Revive_adserver | Revive-adserver | * | 3.2.1 (including) |