Show filters
129 Total Results
Displaying 91-100 of 129
Sort by:
Attacker Value
Unknown
CVE-2018-17180
Disclosure Date: May 17, 2019 (last updated November 27, 2024)
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
0
Attacker Value
Unknown
CVE-2018-18035
Disclosure Date: April 02, 2019 (last updated November 27, 2024)
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
0
Attacker Value
Unknown
CVE-2018-1000218
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..
0
Attacker Value
Unknown
CVE-2018-1000219
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..
0
Attacker Value
Unknown
CVE-2018-15156
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/faxq.php after modifying the "hylafax_server" global variable in interface/super/edit_globals.php.
0
Attacker Value
Unknown
CVE-2018-15150
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in interface/super/edit_globals.php.
0
Attacker Value
Unknown
CVE-2018-15149
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'encounter' parameter.
0
Attacker Value
Unknown
CVE-2018-15152
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.
0
Attacker Value
Unknown
CVE-2018-15155
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php after modifying the "hylafax_enscript" global variable in interface/super/edit_globals.php.
0
Attacker Value
Unknown
CVE-2018-15148
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'text' parameter.
0