HIGH
Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl parameter to modules/patient/mycare2x_pat_info.php; (3) dept_nr or (4) pid parameter to modules/importer/mycare2x_importer.php; (5) myOpsEintrag or (6) keyword parameter in a Suchen action to modules/drg/mycare2x_proc_search.php; or (7) name_last or (8) pid parameter to modules/patient/mycare_pid.php
Published Aug 13, 2012
7.5
HIGHCVSS 2.0
EPSS 1.71%
Description
Affected products
Remediation
Metrics
References (8)
Change history (0)
No recorded changes yet.