exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Revive Adserver 3.0.4 Cross Site Request Forgery

Revive Adserver 3.0.4 Cross Site Request Forgery
Posted May 16, 2014
Authored by Matteo Beccati

Revive Adserver version 3.0.4 and below suffer from multiple cross site request forgery vulnerabilities.

tags | advisory, vulnerability, csrf
advisories | CVE-2013-5954
SHA-256 | 69d5babec7b6252d42e27eec7c6a50d3dbd12263d8c536e4717b434d03fb885d

Revive Adserver 3.0.4 Cross Site Request Forgery

Change Mirror Download
========================================================================
Revive Adserver Security Advisory REVIVE-SA-2014-001
------------------------------------------------------------------------
Advisory ID: REVIVE-SA-2014-001
CVE ID: CVE-2013-5954
Date: 2014-05-15
Security risk: Moderate
Applications affected: Revive Adserver
Versions affected: <= 3.0.4
Versions not affected: >= 3.0.5
Website: http://www.revive-adserver.com/
========================================================================


========================================================================
Vulnerability: CSRF
========================================================================

Description
-----------
A CSRF vulnerability was recently discovered and reported in OpenX
Source Security Advisory CVE-2013-5954. However, the number of places in
the code which were affected go well beyond those listed in the original
advisory.

The vulnerability allows users who are logged into the Revive Adserver
console to be tricked into deleting data from their Revive Adserver
installation. The vulnerability does not allow remote users to access
the Revive Adserver console or otherwise modify data.

Although the attack can cause loss of data and service disruptions, the
risk is rated to be moderate as the vulnerability requires the victim to
interact with the attack mechanism.

The vulnerability is also present and exploitable in OpenX Source 2.8.11
and earlier versions, potentially back to phpAdsNew 2.0.x.

Details
-------
HTTP GET methods are used extensively in the Revive Adserver web console
for deleting data or unlinking accounts etc. instead of HTTP POST. These
older style calls were not protected to prevent attack via CSRF.

The scripts that have been fixed are:

www/admin/admin-user-unlink.php
www/admin/advertiser-delete.php
www/admin/advertiser-user-unlink.php
www/admin/affiliate-delete.php
www/admin/affiliate-user-unlink.php
www/admin/agency-delete.php
www/admin/agency-user-unlink.php
www/admin/banner-delete.php
www/admin/campaign-delete.php
www/admin/channel-delete.php
www/admin/tracker-delete.php,
www/admin/userlog-delete.php
www/admin/zone-delete.php

References
----------
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-5954
https://github.com/revive-adserver/revive-adserver/commit/79cb2db05c9849e225885e8a622978da014a98a7

Permalink
---------
http://www.revive-adserver.com/security/revive-sa-2014-001


Solution
========

We strongly advise people to upgrade to the most recent 3.0.5 version of
Revive Adserver, including those running OpenX Source or older versions
of the application.


Contact Information
===================

The security contact for Revive Adserver can be reached at:
<security AT revive-adserver DOT com>


--
Matteo Beccati
On behalf of the Revive Adserver Team
http://www.revive-adserver.com/
Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close