Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.
| Software | From | Fixed in |
|---|---|---|
| revive-adserver / revive_adserver | - | 5.5.2.x |
| revive-adserver / revive_adserver | 6.0.0 | 6.0.1.x |