CVE-2019-5434 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 57% (pctl 99)
Patch early
A public exploit exists.
Description
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 57.02% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-05-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| revive-sas | revive adserver |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Revive Adserver 4.2 - Remote Code Execution | 2019-12-03 |
References
- http://packetstormsecurity.com/files/155559/Revive-Adserver-4.2-Remote-Code-Execution.html
- https://hackerone.com/reports/512076
- https://hackerone.com/reports/542670
- https://www.revive-adserver.com/security/revive-sa-2019-001/
- http://packetstormsecurity.com/files/155559/Revive-Adserver-4.2-Remote-Code-Execution.html
- https://hackerone.com/reports/512076
- https://hackerone.com/reports/542670
- https://www.revive-adserver.com/security/revive-sa-2019-001/
→ the Explorer · watch your stack · NVD