|
210851
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection …
|
CWE-89
SQL Injection
|
CVE-2020-27239
|
2024-11-21 14:20 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210852
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An att…
|
CWE-89
SQL Injection
|
CVE-2020-27238
|
2024-11-21 14:20 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210853
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page is vulnerable to una…
|
CWE-89
SQL Injection
|
CVE-2020-27237
|
2024-11-21 14:20 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210854
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An attacker can make an authenticated HTTP request to trigger thi…
|
CWE-89
SQL Injection
|
CVE-2020-27236
|
2024-11-21 14:20 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210855
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description parameter. An attacker can make an authenticated HTTP request to trigger this vul…
|
CWE-89
SQL Injection
|
CVE-2020-27235
|
2024-11-21 14:20 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210856
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An attacker can make an authenticated HTTP request to trigger this vuln…
|
CWE-89
SQL Injection
|
CVE-2020-27234
|
2024-11-21 14:20 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210857
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the supplierUID parameter. An attacker can make an authenticated HTTP request to trigger this vul…
|
CWE-89
SQL Injection
|
CVE-2020-27233
|
2024-11-21 14:20 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210858
|
7.8 |
HIGH
Local
|
openclinic_ga_project
|
openclinic_ga
|
An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary can result in privilege escalation. An attacker can replace a …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-27228
|
2024-11-21 14:20 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210859
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web reques…
|
CWE-78
OS Command
|
CVE-2020-27227
|
2024-11-21 14:20 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210860
|
6.0 |
MEDIUM
Local
|
linux fedoraproject debian canonical
|
linux_kernel fedora debian_linux ubuntu_linux
|
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic…
|
CWE-193
Off-by-one Error
|
CVE-2020-27171
|
2024-11-21 14:20 |
2021-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|