Show filters
211 Total Results
Displaying 131-140 of 211
Sort by:
Attacker Value
Unknown
CVE-2017-12711
Disclosure Date: August 30, 2017 (last updated November 26, 2024)
An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that may allow a user to elevate to administrative privileges.
0
Attacker Value
Unknown
CVE-2017-12713
Disclosure Date: August 30, 2017 (last updated November 26, 2024)
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator accounts.
0
Attacker Value
Unknown
CVE-2017-12704
Disclosure Date: August 30, 2017 (last updated November 26, 2024)
A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to the heap-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.
0
Attacker Value
Unknown
CVE-2017-7929
Disclosure Date: May 06, 2017 (last updated November 26, 2024)
An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories.
0
Attacker Value
Unknown
CVE-2016-5810
Disclosure Date: May 02, 2017 (last updated November 26, 2024)
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-5154
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files.
0
Attacker Value
Unknown
CVE-2017-5152
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted (AUTHENTICATION BYPASS).
0
Attacker Value
Unknown
CVE-2016-5817
Disclosure Date: August 22, 2016 (last updated November 25, 2024)
SQL injection vulnerability in news pages in Cargotec Navis WebAccess before 2016-08-10 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4528
Disclosure Date: June 25, 2016 (last updated November 25, 2024)
Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.
0
Attacker Value
Unknown
CVE-2016-4525
Disclosure Date: June 25, 2016 (last updated November 25, 2024)
Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensitive information or modify data via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.
0