Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
broadwin webaccess vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2012-1234
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
6.4
CVSSv2
CVE-2012-0237
Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
6
CVSSv2
CVE-2012-1235
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
6
CVSSv2
CVE-2012-0235
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
5
CVSSv2
CVE-2012-0241
Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to cause a denial of service (memory corruption) via a modified stream identifier to a function.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
2 EDB exploits
5
CVSSv2
CVE-2012-0236
Advantech/BroadWin WebAccess 7.0 and previous versions allows remote malicious users to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
5
CVSSv2
CVE-2012-0239
uaddUpAdmin.asp in Advantech/BroadWin WebAccess prior to 7.0 does not properly perform authentication, which allows remote malicious users to modify an administrative password via a password-change request.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
4.3
CVSSv2
CVE-2011-4522
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to inject arbitrary web script or HTML via unspecified parameters.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
4.3
CVSSv2
CVE-2011-4523
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to inject arbitrary web script or HTML via unspecified parameters.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
4.3
CVSSv2
CVE-2012-0233
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to inject arbitrary web script or HTML via a malformed URL.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »