CVE-2013-4619 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_range.php or the (3) form_newid parameter to custom/chart_tracker.php.
Reference
http://secunia.com/advisories/54083 http://sourceforge.net/p/openemr/code/ci/8a8a4607ba5ae2b9eb6b6a3b1b8ed7c6ea7e03b1/ http://sourceforge.net/p/openemr/discussion/202506/thread/4854b2b1/9658 https://www.trustwave.com/spiderlabs/advisories/TWSL2013-018.txt
Share on: