Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2018-15705
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2018-15707
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
0
Attacker Value
Unknown
CVE-2018-15706
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
0