CVE-2016-9470: Revive-Adserver Revive Adserver
Critical severity, CVSS 9.0. EPSS: 2.1% chance of exploitation in the next 30 days.
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually downloading a file from a trusted domain.
Affected products
- Revive-Adserver Revive Adserver: up to and including 3.2.4; version 4.0.0 only
Published 2017-03-28. Last modified 2026-06-17.