Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
advantech advantech webaccess 7.0 vulnerabilities and exploits
(subscribe to this query)
890
VMScore
CVE-2012-0243
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
890
VMScore
CVE-2011-4525
Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
445
VMScore
CVE-2012-0236
Advantech/BroadWin WebAccess 7.0 and previous versions allows remote malicious users to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
578
VMScore
CVE-2012-1234
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
534
VMScore
CVE-2012-1235
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
1000
VMScore
CVE-2011-4041
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote malicious users to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.
Broadwin Webaccess
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4