Show filters
123 Total Results
Displaying 81-90 of 123
Sort by:
Attacker Value
Unknown
CVE-2018-17393
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.
0
Attacker Value
Unknown
CVE-2018-1000839
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
0
Attacker Value
Unknown
CVE-2018-1000650
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.
0
Attacker Value
Unknown
CVE-2018-1000646
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
0
Attacker Value
Unknown
CVE-2018-1000645
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function.
0
Attacker Value
Unknown
CVE-2018-1000649
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled input.
0
Attacker Value
Unknown
CVE-2018-1000647
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.
0
Attacker Value
Unknown
CVE-2018-1000648
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.
0
Attacker Value
Unknown
CVE-2016-10684
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
healthcenter - IBM Monitoring and Diagnostic Tools health Center agent healthcenter downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown
CVE-2017-14101
Disclosure Date: December 15, 2017 (last updated November 26, 2024)
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP request to the vulnerable service allows for arbitrary file read access to the local file system as well as the transmittal of the application service's account hashed credentials to a remote attacker.
0