Show filters
129 Total Results
Displaying 101-110 of 129
Sort by:
Attacker Value
Unknown

CVE-2018-15153

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the "hylafax_server" global variable in interface/super/edit_globals.php.
0
Attacker Value
Unknown

CVE-2018-15151

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.
0
Attacker Value
Unknown

CVE-2018-15154

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/billing/sl_eob_search.php after modifying the "print_command" global variable in interface/super/edit_globals.php.
0
Attacker Value
Unknown

CVE-2018-15146

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.
0
Attacker Value
Unknown

CVE-2018-15147

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'id' parameter.
0
Attacker Value
Unknown

CVE-2018-15143

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) catid or (2) providerid parameter.
0
Attacker Value
Unknown

CVE-2018-15145

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) eid, (2) userid, or (3) pid parameter.
0
Attacker Value
Unknown

CVE-2018-15141

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.
0
Attacker Value
Unknown

CVE-2018-15144

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/de_identification_forms/find_drug_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the search_term parameter.
0
Attacker Value
Unknown

CVE-2018-15140

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get.
0