An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/95741 | Third Party Advisory VDB Entry |
https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dc | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2017-01-23T17:00:00
Updated: 2017-01-25T10:57:01
Reserved: 2017-01-23T00:00:00
Link: CVE-2017-5569
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-01-23T17:59:00.143
Modified: 2017-01-26T13:53:58.837
Link: CVE-2017-5569
JSON object: View
Redhat Information
No data.
CWE