Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mahmoud Khaled

#22123of 56,333
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-52648
6.1
2026-06-26
Unknown · Revive Adserver · CVE-2026-50740
**Name of the Vulnerable Software and Affected Versions** Revive Adserver versions prior to 6.0.8 **Description** Insufficient sanitization of user input in the 'zone-include.php' script allows a low-privileged user to execute reflected Cross-Site Scripting (XSS) attacks. This occurs through the `refresh` parameter of the iFrame invocation tag. **Recommendations** Update to a version newer than 6.0.7. As a temporary mitigation, restrict access to the 'zone-include.php' script or avoid using the `refresh` parameter in iFrame invocation tags.
PT-2026-52652
6.1
2026-06-26
Revive · Andserver · CVE-2026-50745
**Name of the Vulnerable Software and Affected Versions** The product name cannot be determined (affected versions not specified) **Description** A missing sanitisation issue exists in the `stats-video.php` script. The construction of URLs to this script does not follow best practices, and the output of the Smarty custom helper function `url()` is neither properly encoded nor sanitised. This allows user-supplied input to be reflected without escaping, leading to Cross-Site Scripting (XSS), where malicious scripts are injected into benign websites. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.