Search Results (5 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-5399 2 Invensys, Schneider Electric 2 Wonderware Information Server, Wonderware Information Server Portal 2025-11-01 N/A
SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2014-5398 2 Invensys, Schneider Electric 2 Wonderware Information Server, Wonderware Information Server Portal 2025-11-01 N/A
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVE-2014-5397 2 Invensys, Schneider Electric 2 Wonderware Information Server, Wonderware Information Server Portal 2025-11-01 N/A
Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-2381 2 Invensys, Schneider Electric 2 Wonderware Information Server, Wonderware Information Server Portal 2025-11-01 N/A
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.
CVE-2014-2380 2 Invensys, Schneider Electric 2 Wonderware Information Server, Wonderware Information Server Portal 2025-11-01 N/A
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.