Show filters
325 Total Results
Displaying 151-160 of 325
Sort by:
Attacker Value
Unknown

CVE-2020-12010

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.
Attacker Value
Unknown

CVE-2020-12018

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data.
Attacker Value
Unknown

CVE-2020-12002

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.
Attacker Value
Unknown

CVE-2020-12014

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.
Attacker Value
Unknown

CVE-2020-10623

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.
Attacker Value
Unknown

CVE-2020-10617

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.
Attacker Value
Unknown

CVE-2020-10631

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
Attacker Value
Unknown

CVE-2020-10619

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
Attacker Value
Unknown

CVE-2020-10625

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.
Attacker Value
Unknown

CVE-2020-10603

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.