NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83655 | CVE-2016-9368 | An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating. | 2 | 5 | Medium | 2017-03-18 | 2017-03-14 | View | |
82371 | CVE-2016-8341 | An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host"s database could be subject to read, write, and delete commands. | 2017-02-15 | 2017-02-14 | View | ||||
81668 | CVE-2017-5598 | An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects the EmployeePortalServlet page and the following parameter: employer. | 2 | 5 | Medium | 2017-02-07 | 2017-01-31 | View | |
81657 | CVE-2017-5570 | An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile(). | 2 | 6.5 | Medium | 2017-02-07 | 2017-01-26 | View | |
81656 | CVE-2017-5569 | An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile(). | 2 | 7.5 | High | 2017-02-07 | 2017-01-26 | View |
Page 1149 of 17672, showing 5 records out of 88360 total, starting on record 5741, ending on 5745