Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown
CVE-2011-4522
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown
CVE-2011-4525
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-0240
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-0233
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.
0
Attacker Value
Unknown
CVE-2012-0238
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-0239
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.
0
Attacker Value
Unknown
CVE-2011-4523
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown
CVE-2012-1234
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
0
Attacker Value
Unknown
CVE-2011-4524
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified parameters.
0
Attacker Value
Unknown
CVE-2012-0244
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
0