Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
advantech vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2011-4524
Buffer overflow in Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to execute arbitrary code via a long string value in unspecified parameters.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
10
CVSSv2
CVE-2011-4525
Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
10
CVSSv2
CVE-2011-4526
Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess prior to 7.0 might allow remote malicious users to execute arbitrary code via a long string value in unspecified parameters.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
6.5
CVSSv2
CVE-2012-1234
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
6
CVSSv2
CVE-2012-1235
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
7.5
CVSSv2
CVE-2012-0234
SQL injection vulnerability in Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to execute arbitrary SQL commands via a malformed URL.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
5
CVSSv2
CVE-2012-0236
Advantech/BroadWin WebAccess 7.0 and previous versions allows remote malicious users to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
6.4
CVSSv2
CVE-2012-0237
Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
5
CVSSv2
CVE-2012-0239
uaddUpAdmin.asp in Advantech/BroadWin WebAccess prior to 7.0 does not properly perform authentication, which allows remote malicious users to modify an administrative password via a password-change request.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
10
CVSSv2
CVE-2012-0240
GbScriptAddUp.asp in Advantech/BroadWin WebAccess prior to 7.0 does not properly perform authentication, which allows remote malicious users to execute arbitrary code via unspecified vectors.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »