<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 12:41:17 +0000</lastBuildDate>
    <item>
      <title>CVE-2014-0771 — Advantech WebAccess File and Directory Information Exposure</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2014-0771</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Advantech WebAccess&lt;/p&gt;
&lt;p&gt;The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
“OpenUrlToBuffer.” This method takes a URL as a parameter and returns 
its contents to the caller in JavaScript. The URLs are accessed in the 
security context of the current browser session. The control does not 
perform any URL validation and allows “file://” URLs that access the 
local disk.&lt;/p&gt;
&lt;p&gt;The method can be used to open a URL (including file URLs) and read 
file URLs through JavaScript. This method could also be used to reach 
any arbitrary URL to which the browser has access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Advantech WebAccess&lt;/p&gt;
&lt;p&gt;The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
“OpenUrlToBuffer.” This method takes a URL as a parameter and returns 
its contents to the caller in JavaScript. The URLs are accessed in the 
security context of the current browser session. The control does not 
perform any URL validation and allows “file://” URLs that access the 
local disk.&lt;/p&gt;
&lt;p&gt;The method can be used to open a URL (including file URLs) and read 
file URLs through JavaScript. This method could also be used to reach 
any arbitrary URL to which the browser has access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2014-0771</guid>
    </item>
  </channel>
</rss>
