Show filters
125 Total Results
Displaying 31-40 of 125
Sort by:
Attacker Value
Unknown

CVE-2023-33481

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.
Attacker Value
Unknown

CVE-2023-33480

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by a lack of input validation and access control in the staff/register.php endpoint and the edit-my-profile.php page. By sending a series of specially crafted requests to the RemoteClinic application, an attacker can create admin users with more privileges than their own, upload a PHP file containing arbitrary code, and execute arbitrary commands via the PHP shell.
Attacker Value
Unknown

CVE-2023-33479

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
Attacker Value
Unknown

CVE-2023-33478

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
Attacker Value
Unknown

CVE-2023-2824

Disclosure Date: May 20, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-21993

Disclosure Date: April 18, 2023 (last updated October 08, 2023)
Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Clinical Remote Data Capture accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Attacker Value
Unknown

CVE-2023-25931

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy application, which has greater control over therapy parameters than the patient app. Changes still cannot be made outside of the established therapy parameters of the programmer. For unauthorized access to occur, an individual would need physical access to the Smart Programmer.
Attacker Value
Unknown

CVE-2022-31405

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.
Attacker Value
Unknown

CVE-2023-1037

Disclosure Date: February 26, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /APR/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221795.
Attacker Value
Unknown

CVE-2023-1036

Disclosure Date: February 26, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /APR/signup.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221794 is the identifier assigned to this vulnerability.