Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown

CVE-2018-1000839

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
0
Attacker Value
Unknown

CVE-2018-1000650

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.
0
Attacker Value
Unknown

CVE-2018-1000646

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
0
Attacker Value
Unknown

CVE-2018-1000645

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function.
0
Attacker Value
Unknown

CVE-2018-1000649

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled input.
0
Attacker Value
Unknown

CVE-2018-1000647

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.
0
Attacker Value
Unknown

CVE-2018-1000648

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.
0
Attacker Value
Unknown

CVE-2016-6152

Disclosure Date: July 26, 2016 (last updated November 25, 2024)
CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-6151

Disclosure Date: July 26, 2016 (last updated November 25, 2024)
CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-1899

Disclosure Date: May 16, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CA eHealth 6.0.x, 6.1.x, 6.2.1, and 6.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0