Vulnerabilities > Advantech > Advantech Webaccess

DATE CVE VULNERABILITY TITLE RISK
2014-04-12 CVE-2014-0765 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Advantech Webaccess 5.0/6.0/7.0
Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long GotoCmd argument.
network
low complexity
advantech CWE-119
7.5
2014-04-12 CVE-2014-0764 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Advantech Webaccess 5.0/6.0/7.0
Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName parameter.
network
low complexity
advantech CWE-119
7.5
2014-04-12 CVE-2014-0763 SQL Injection vulnerability in Advantech Webaccess 5.0/6.0/7.0
Multiple SQL injection vulnerabilities in DBVisitor.dll in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary SQL commands via SOAP requests to unspecified functions.
network
low complexity
advantech CWE-89
7.5
2013-08-22 CVE-2013-2299 Cross-Site Scripting vulnerability in Advantech Webaccess 5.0/6.0/7.0
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
advantech CWE-79
3.5
2012-02-21 CVE-2012-1235 Cross-Site Request Forgery (CSRF) vulnerability in Advantech Webaccess 5.0/6.0
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
network
advantech CWE-352
6.0
2012-02-21 CVE-2012-1234 SQL Injection vulnerability in Advantech Webaccess 5.0/6.0
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL.
network
low complexity
advantech CWE-89
6.5
2012-02-21 CVE-2012-0244 SQL Injection vulnerability in Advantech Webaccess 5.0/6.0
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
network
low complexity
advantech CWE-89
7.5
2012-02-21 CVE-2012-0243 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Advantech Webaccess 5.0/6.0
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.
network
low complexity
advantech CWE-119
critical
10.0
2012-02-21 CVE-2012-0242 USE of Externally-Controlled Format String vulnerability in Advantech Webaccess 5.0/6.0
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.
network
low complexity
advantech CWE-134
critical
10.0
2012-02-21 CVE-2012-0241 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Advantech Webaccess 5.0/6.0
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.
network
low complexity
advantech CWE-119
5.0