Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2014-2365

Disclosure Date: July 19, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-2368

Disclosure Date: July 19, 2014 (last updated October 05, 2023)
The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.
0
Attacker Value
Unknown

CVE-2014-2367

Disclosure Date: July 19, 2014 (last updated October 05, 2023)
The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.
0
Attacker Value
Unknown

CVE-2014-2366

Disclosure Date: July 19, 2014 (last updated October 05, 2023)
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.
0
Attacker Value
Unknown

CVE-2014-2364

Disclosure Date: July 19, 2014 (last updated October 05, 2023)
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.
0
Attacker Value
Unknown

CVE-2014-0771

Disclosure Date: April 12, 2014 (last updated October 05, 2023)
The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL.
0
Attacker Value
Unknown

CVE-2014-0764

Disclosure Date: April 12, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName parameter.
0
Attacker Value
Unknown

CVE-2014-0763

Disclosure Date: April 12, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in DBVisitor.dll in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary SQL commands via SOAP requests to unspecified functions.
0
Attacker Value
Unknown

CVE-2014-0765

Disclosure Date: April 12, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long GotoCmd argument.
0
Attacker Value
Unknown

CVE-2014-0766

Disclosure Date: April 12, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName2 argument.
0