Show filters
211 Total Results
Displaying 51-60 of 211
Sort by:
Attacker Value
Unknown
CVE-2020-10617
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.
0
Attacker Value
Unknown
CVE-2020-10631
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
0
Attacker Value
Unknown
CVE-2020-10619
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
0
Attacker Value
Unknown
CVE-2020-10625
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.
0
Attacker Value
Unknown
CVE-2020-10603
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.
0
Attacker Value
Unknown
CVE-2020-10629
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.
0
Attacker Value
Unknown
CVE-2020-10621
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).
0
Attacker Value
Unknown
CVE-2019-3942
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.
0
Attacker Value
Unknown
CVE-2020-10607
Disclosure Date: March 27, 2020 (last updated February 21, 2025)
In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.
0
Attacker Value
Unknown
CVE-2019-3951
Disclosure Date: December 12, 2019 (last updated November 27, 2024)
Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a stack-based buffer overflow when handling IOCTL 70533 RPC messages.
0