Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.
Advantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.
Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.220170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.
A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.220170817. An attacker has read access to files within the directory structure of the target device.