CVE-2014-0771

N/A Unknown
Published: April 12, 2014 Modified: May 06, 2026
View on NVD

Description

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the current browser session. The control does not perform any URL validation and allows “file://” URLs that access the local disk. The method can be used to open a URL (including file URLs) and read file URLs through JavaScript. This method could also be used to reach any arbitrary URL to which the browser has access.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://webaccess.advantech.com/
Source: ics-cert@hq.dhs.gov
http://www.securityfocus.com/bid/66740
Source: ics-cert@hq.dhs.gov
http://ics-cert.us-cert.gov/advisories/ICSA-14-079-03
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource

4 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.3%
57th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

advantech