Show filters
36 Total Results
Displaying 31-36 of 36
Sort by:
Attacker Value
Unknown
CVE-2011-4521
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string input.
0
Attacker Value
Unknown
CVE-2012-0237
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
0
Attacker Value
Unknown
CVE-2012-1235
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
0
Attacker Value
Unknown
CVE-2012-0243
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.
0
Attacker Value
Unknown
CVE-2012-0234
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.
0
Attacker Value
Unknown
CVE-2012-0241
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.
0