Vulnerabilities > Advantech > Iview

DATE CVE VULNERABILITY TITLE RISK
2020-07-15 CVE-2020-14507 Path Traversal vulnerability in Advantech Iview 5.6
Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
network
low complexity
advantech CWE-22
critical
9.8
2020-07-15 CVE-2020-14505 Injection vulnerability in Advantech Iview 5.6
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability.
network
low complexity
advantech CWE-74
critical
9.8
2020-07-15 CVE-2020-14497 SQL Injection vulnerability in Advantech Iview 5.6
Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries.
network
low complexity
advantech CWE-89
critical
9.8