Impact
A flaw in Revive Adserver 6.0.6 and earlier permits a low‑privileged user to insert an unexpected "component" parameter when saving delivery limitations. This unsanitised input is stored in the compiledlimitations field and later executed as PHP code during banner delivery, resulting in remote code execution on the host server. The vulnerability is a classic code‑injection flaw (CWE-94) that threatens confidentiality, integrity, and availability of the entire web application environment.
Affected Systems
Revive Adserver, versions 6.0.6 and earlier, may be affected. A low‑privileged user account with permission to edit delivery limitations can exploit the flaw during the banner delivery process.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. EPSS data is unavailable, but the lack of a KEV listing suggests no publicly known exploits yet. The likely attack vector is through the web UI where delivery limitations are edited. An attacker would need a valid low‑privileged account and the ability to save a delivery limitation; the flaw allows arbitrary PHP code injection, enabling full control of the server.
OpenCVE Enrichment