VendorsAdvantechadvantech_webaccess5.0
Vulnerabilities

Advantech /BroadWin WebAccess 5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2012-0242
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.
Published 2012-02-21 · Modified
10.01 PoCEPSS 0.072
CVE-2012-0240
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.
Published 2012-02-21 · Modified
10.0EPSS 0.043
CVE-2012-0243
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.
Published 2012-02-21 · Modified
10.0EPSS 0.043
CVE-2011-4524
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified parameters.
Published 2012-02-21 · Modified
10.0EPSS 0.043
CVE-2011-4526
Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote attackers to execute arbitrary code via a long string value in unspecified parameters.
Published 2012-02-21 · Modified
10.0EPSS 0.043
CVE-2012-0238
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.
Published 2012-02-21 · Modified
10.0EPSS 0.043
CVE-2011-4525
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.
Published 2012-02-21 · Modified
10.0EPSS 0.022
CVE-2014-2366
Advantech WebAccess Cleartext Storage of Sensitive Information in Memory
Published 2014-07-19 · Modified
9.0EPSS 0.013
CVE-2014-2364
Advantech WebAccess Stack-Based Buffer Overflow
Published 2014-07-19 · Modified
7.51 PoCEPSS 0.614
CVE-2014-0763
Advantech WebAccess SQL Injection
Published 2014-04-12 · Modified
7.5EPSS 0.192
CVE-2014-0768
Advantech WebAccess Stack-based Buffer Overflow
Published 2014-04-12 · Modified
7.5EPSS 0.027
CVE-2014-0767
Advantech WebAccess Stack-based Buffer Overflow
Published 2014-04-12 · Modified
7.5EPSS 0.027
CVE-2014-0764
Advantech WebAccess Stack-based Buffer Overflow
Published 2014-04-12 · Modified
7.5EPSS 0.027
CVE-2014-0765
Advantech WebAccess Stack-based Buffer Overflow
Published 2014-04-12 · Modified
7.5EPSS 0.027
CVE-2014-0766
Advantech WebAccess Stack-based Buffer Overflow
Published 2014-04-12 · Modified
7.5EPSS 0.027
CVE-2014-0770
Advantech WebAccess Stack-based Buffer Overflow
Published 2014-04-12 · Modified
7.5EPSS 0.026
CVE-2014-0773
Advantech WebAccess Command Injection
Published 2014-04-12 · Modified
7.5EPSS 0.025
CVE-2014-2368
Advantech WebAccess Unsafe ActiveX Control Marked Safe For Scripting
Published 2014-07-19 · Modified
7.5EPSS 0.017
CVE-2014-2367
Advantech WebAccess Authentication Bypass Issues
Published 2014-07-19 · Modified
7.5EPSS 0.015
CVE-2014-0771
Advantech WebAccess File and Directory Information Exposure
Published 2014-04-12 · Modified
7.5EPSS 0.014
CVE-2011-4521
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string input.
Published 2012-02-21 · Modified
7.5EPSS 0.012
CVE-2012-0244
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
Published 2012-02-21 · Modified
7.5EPSS 0.012
CVE-2012-0234
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.
Published 2012-02-21 · Modified
7.5EPSS 0.012
CVE-2014-2365
Advantech WebAccess Improper Access Control
Published 2014-07-19 · Modified
6.5EPSS 0.016
CVE-2012-1234
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
Published 2012-02-21 · Modified
6.5EPSS 0.012
CVE-2012-0237
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
Published 2012-02-21 · Modified
6.4EPSS 0.013
CVE-2012-1235
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
Published 2012-02-21 · Modified
6.0EPSS 0.005
CVE-2012-0235
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Published 2012-02-21 · Modified
6.0EPSS 0.005
CVE-2012-0241
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.
Published 2012-02-21 · Modified
5.02 PoCEPSS 0.049
CVE-2014-0772
Advantech WebAccess File and Directory Information Exposure
Published 2014-04-12 · Modified
5.0EPSS 0.014
CVE-2012-0236
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
Published 2012-02-21 · Modified
5.0EPSS 0.013
CVE-2012-0239
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.
Published 2012-02-21 · Modified
5.0EPSS 0.012
CVE-2012-0233
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.
Published 2012-02-21 · Modified
4.3EPSS 0.010
CVE-2011-4523
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Published 2012-02-21 · Modified
4.3EPSS 0.010
CVE-2011-4522
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Published 2012-02-21 · Modified
4.3EPSS 0.010
CVE-2013-2299
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2013-08-22 · Modified
3.51 PoCEPSS 0.014