|
246691
|
9.8 |
CRITICAL
Network
|
open-emr
|
openemr
|
Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) eid, (2) userid, o…
|
CWE-89
SQL Injection
|
CVE-2018-15145
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246692
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
SQL injection vulnerability in interface/de_identification_forms/find_drug_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via…
|
CWE-89
SQL Injection
|
CVE-2018-15144
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246693
|
9.8 |
CRITICAL
Network
|
open-emr
|
openemr
|
Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) catid or (2) prov…
|
CWE-89
SQL Injection
|
CVE-2018-15143
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246694
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file wi…
|
CWE-22
Path Traversal
|
CVE-2018-15142
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246695
|
6.5 |
MEDIUM
Network
|
open-emr
|
openemr
|
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" paramete…
|
CWE-22
Path Traversal
|
CVE-2018-15141
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246696
|
6.5 |
MEDIUM
Network
|
open-emr
|
openemr
|
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter …
|
CWE-22
Path Traversal
|
CVE-2018-15140
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246697
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-15139
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246698
|
6.5 |
MEDIUM
Network
|
hotel_booking_script_project
|
hotel_booking_script
|
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15191
|
2024-11-21 12:50 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246699
|
5.4 |
MEDIUM
Network
|
hotel_booking_script_project
|
hotel_booking_script
|
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15190
|
2024-11-21 12:50 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246700
|
5.4 |
MEDIUM
Network
|
advanced_real_estate_script_project
|
advanced_real_estate_script
|
PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15189
|
2024-11-21 12:50 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|