VendorsEsi Productswebeocany version
Vulnerabilities

Esi Products Webeoc any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2005-2286
WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
Published 2005-07-17 · Modified
10.0EPSS 0.022
CVE-2005-2284
Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors.
Published 2005-07-17 · Modified
7.5EPSS 0.012
CVE-2005-4029
WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out valid users via brute force methods.
Published 2005-12-05 · Modified
5.0EPSS 0.013
CVE-2005-2285
WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Usernames, Passwords, Emergency information, medical information, and system configuration.
Published 2005-07-17 · Modified
5.0EPSS 0.013
CVE-2005-4002
WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.
Published 2005-12-05 · Modified
4.0EPSS 0.010
CVE-2005-2283
WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file.
Published 2005-07-17 · Modified
2.1EPSS 0.005