|
296831
|
- |
|
advantech
|
advantech_webaccess
|
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
|
CWE-89
SQL Injection
|
CVE-2012-0244
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296832
|
- |
|
advantech
|
advantech_webaccess
|
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0243
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296833
|
- |
|
advantech
|
advantech_webaccess
|
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2012-0242
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296834
|
- |
|
advantech
|
advantech_webaccess
|
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0241
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296835
|
- |
|
advantech
|
advantech_webaccess
|
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2012-0240
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296836
|
- |
|
advantech
|
advantech_webaccess
|
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.
|
CWE-287
Improper Authentication
|
CVE-2012-0239
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296837
|
- |
|
advantech
|
advantech_webaccess
|
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0238
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296838
|
- |
|
advantech
|
advantech_webaccess
|
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0237
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296839
|
- |
|
advantech
|
advantech_webaccess
|
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security…
|
CWE-200
Information Exposure
|
CVE-2012-0236
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296840
|
- |
|
advantech
|
advantech_webaccess
|
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2012-0235
|
2024-11-21 10:34 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|