CVE-2021-22654
- EPSS 0.42%
- Veröffentlicht 11.02.2021 18:15:17
- Zuletzt bearbeitet 21.11.2024 05:50:24
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.
CVE-2021-22656
- EPSS 1.86%
- Veröffentlicht 11.02.2021 18:15:17
- Zuletzt bearbeitet 21.11.2024 05:50:25
Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files.
CVE-2020-16245
- EPSS 15.93%
- Veröffentlicht 25.08.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:00
Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
CVE-2020-14503
- EPSS 0.87%
- Veröffentlicht 15.07.2020 03:15:50
- Zuletzt bearbeitet 21.11.2024 05:03:24
Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an attacker to remotely execute arbitrary code.
CVE-2020-14501
- EPSS 0.34%
- Veröffentlicht 15.07.2020 03:15:50
- Zuletzt bearbeitet 21.11.2024 05:03:24
Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user table, including the administrato...
CVE-2020-14499
- EPSS 0.42%
- Veröffentlicht 15.07.2020 03:15:50
- Zuletzt bearbeitet 21.11.2024 05:03:24
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.
CVE-2020-14497
- EPSS 1.68%
- Veröffentlicht 15.07.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:23
Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify in...
CVE-2020-14507
- EPSS 1.73%
- Veröffentlicht 15.07.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:25
Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
CVE-2020-14505
- EPSS 3%
- Veröffentlicht 15.07.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:24
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request ...