Show filters
211 Total Results
Displaying 191-200 of 211
Sort by:
Attacker Value
Unknown

CVE-2011-4525

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-0240

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-0233

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.
0
Attacker Value
Unknown

CVE-2011-4523

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown

CVE-2012-0244

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
0
Attacker Value
Unknown

CVE-2012-1234

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
0
Attacker Value
Unknown

CVE-2011-4524

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified parameters.
0
Attacker Value
Unknown

CVE-2011-4521

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string input.
0
Attacker Value
Unknown

CVE-2012-0237

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
0
Attacker Value
Unknown

CVE-2012-1235

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
0