CVE-2012-1234
21.02.2012, 13:31
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
| Vendor | Product | Version |
|---|---|---|
| advantech | advantech_webaccess | 𝑥 ≤ 6.0 |
| advantech | advantech_webaccess | 5.0 |
𝑥
= Vulnerable software versions