Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
eClinicalWorks Patient Portal SQL注入漏洞
Vulnerability Description
eClinicalWorks Patient Portal是美国eClinicalWorks公司的一款应用于医疗领域的产品,该产品为患者提供了一个安全的查看他们的个人健康记录(PHR)和查看化验结果等的通信方式。 eClinicalWorks Patient Portal 7.0 build 13版本中的template.jsp文件存在SQL注入漏洞。攻击者可通过发送HTTP POST请求利用该漏洞将数据库数据转储到恶意的服务器。
CVSS Information
N/A
Vulnerability Type
N/A