Vulnerabilities (CVE)

Filtered by vendor Spidercontrol Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3329 1 Spidercontrol 1 Scadawebserver 2023-08-08 N/A 6.5 MEDIUM
SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a denial-of-service condition.
CVE-2018-18991 1 Spidercontrol 1 Scada Webserver 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted URL that contains JavaScript, which can be reflected off the web application to the victim's browser.