Multiple stack-based buffer overflows in Advantech WebAccess prior to 7.2 allow remote malicious users to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
advantech advantech webaccess 7.0 |
||
advantech advantech webaccess 6.0 |
||
advantech advantech webaccess 5.0 |
||
advantech advantech webaccess |