Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2015-4453

Disclosure Date: July 05, 2015 (last updated October 05, 2023)
interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive information via an ignoreAuth=1 value to certain scripts, as demonstrated by (1) interface/fax/fax_dispatch_newpid.php and (2) interface/billing/sl_eob_search.php.
0
Attacker Value
Unknown

CVE-2013-4619

Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_range.php, or the (3) form_newid parameter to custom/chart_tracker.php.
0
Attacker Value
Unknown

CVE-2013-4620

Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the note parameter.
0
Attacker Value
Unknown

CVE-2011-5161

Disclosure Date: September 09, 2012 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the patient directory under documents/.
0
Attacker Value
Unknown

CVE-2011-5160

Disclosure Date: September 09, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site parameter.
0