CVE-2014-0771

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the current browser session. The control does not perform any URL validation and allows “file://” URLs that access the local disk. The method can be used to open a URL (including file URLs) and read file URLs through JavaScript. This method could also be used to reach any arbitrary URL to which the browser has access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:advantech:advantech_webaccess:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:5.0:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:6.0:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:7.0:*:*:*:*:*:*:*

History

19 Sep 2025, 20:15

Type Values Removed Values Added
References
  • () http://webaccess.advantech.com/ -
  • () http://www.securityfocus.com/bid/66740 -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-14-079-03 -
CVSS v2 : 5.0
v3 : unknown
v2 : 7.5
v3 : unknown
CWE CWE-538
Summary (en) The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. (en) The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the current browser session. The control does not perform any URL validation and allows “file://” URLs that access the local disk. The method can be used to open a URL (including file URLs) and read file URLs through JavaScript. This method could also be used to reach any arbitrary URL to which the browser has access.

21 Nov 2024, 02:02

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/advisories/ICSA-14-079-03 - US Government Resource () http://ics-cert.us-cert.gov/advisories/ICSA-14-079-03 - US Government Resource

Information

Published : 2014-04-12 04:37

Updated : 2025-09-19 20:15


NVD link : CVE-2014-0771

Mitre link : CVE-2014-0771

CVE.ORG link : CVE-2014-0771


JSON object : View

Products Affected

advantech

  • advantech_webaccess
CWE
CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor