Show filters
563 Total Results
Displaying 261-270 of 563
Sort by:
Attacker Value
Unknown
CVE-2020-27230
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-27231
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-27226
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-24243
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.
0
Attacker Value
Unknown
CVE-2021-24244
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
0
Attacker Value
Unknown
CVE-2021-31778
Disclosure Date: April 28, 2021 (last updated February 22, 2025)
The media2click (aka 2 Clicks for External Media) extension 1.x before 1.3.3 for TYPO3 allows XSS by a backend user account.
0
Attacker Value
Unknown
CVE-2021-28168
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.
0
Attacker Value
Unknown
CVE-2021-28167
Disclosure Date: April 21, 2021 (last updated February 22, 2025)
In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without running the class initialization method, and may allow a user to observe uninitialized values.
0
Attacker Value
Unknown
CVE-2021-31329
Disclosure Date: April 21, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
0
Attacker Value
Unknown
CVE-2021-31327
Disclosure Date: April 21, 2021 (last updated February 22, 2025)
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
0