<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T16:24:39.704452+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2014-0772</id>
    <title>CVE-2014-0772 — Advantech WebAccess File and Directory Information Exposure</title>
    <updated>2026-10-07T16:24:39.706176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Advantech WebAccess</p>
<p>The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
OpenUrlToBufferTimeout. This method takes a URL as a parameter and 
returns its contents to the caller in JavaScript. The URLs are accessed 
in the security context of the current browser session. The control does
 not perform any URL validation and allows file:// URLs that access the 
local disk.</p>
<p>The method can be used to open a URL (including file URLs) and read 
the URLs through JavaScript. This method could also be used to reach any
 arbitrary URL to which the browser has access.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2014-0772"/>
  </entry>
</feed>
