CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2012-0233 Advantech/BroadWin WebAccess Multiple Vulnerabilities

2018年1月2日 2280点热度 0人点赞 0条评论

漏洞类别:CGI

漏洞等级:

漏洞信息

Advantech/BroadWin WebAccess is a web-based application for human-machine interfaces (HMI), and supervisory control and data acquisition (SCADA).

Advantech/BroadWin WebAccess is exposed to multiple vulnerabilities that can cause Cross-site scripting (XSS), SQL injection, Cross-site report forgery (CSRF) and Authentication issues.

Affected Versions:
Advantech/BroadWin WebAccess 7.0 and earlier

QID Detection Logic (unauthenticated):
The QID sends a GET /broadWeb/bwRoot.asp request to retrieve the version of Advantech/BroadWin WebAccess running on the remote target.

漏洞危害

Successful exploitation of the vulnerabilities will lead to:
1) Cross-site scripting (XSS)
2) SQL injection
3) Cross-site report forgery (CSRF)
4) Authentication issues

解决方案

Customers are advised to upgrade to the latet version of the software. Refer to the following link for further details:Advantech WebAccess

Patch:
Following are links for downloading patches to fix the vulnerabilities:

Advantech/BroadWin WebAccess

0daybank

标签: 暂无
最后更新:2018年1月2日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me