Show filters
129 Total Results
Displaying 91-100 of 129
Sort by:
Attacker Value
Unknown

CVE-2018-17180

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
0
Attacker Value
Unknown

CVE-2018-18035

Disclosure Date: April 02, 2019 (last updated November 27, 2024)
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
0
Attacker Value
Unknown

CVE-2018-1000218

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..
0
Attacker Value
Unknown

CVE-2018-1000219

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..
0
Attacker Value
Unknown

CVE-2018-15156

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/faxq.php after modifying the "hylafax_server" global variable in interface/super/edit_globals.php.
0
Attacker Value
Unknown

CVE-2018-15150

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in interface/super/edit_globals.php.
0
Attacker Value
Unknown

CVE-2018-15149

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'encounter' parameter.
0
Attacker Value
Unknown

CVE-2018-15152

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.
Attacker Value
Unknown

CVE-2018-15155

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php after modifying the "hylafax_enscript" global variable in interface/super/edit_globals.php.
0
Attacker Value
Unknown

CVE-2018-15148

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'text' parameter.
0