CVE Database
/

CVE-2012-4260

Back to search

CVE-2012-4260

Published: Aug 13, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl parameter to modules/patient/mycare2x_pat_info.php; (3) dept_nr or (4) pid parameter to modules/importer/mycare2x_importer.php; (5) myOpsEintrag or (6) keyword parameter in a Suchen action to modules/drg/mycare2x_proc_search.php; or (7) name_last or (8) pid parameter to modules/patient/mycare_pid.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

81686
vdb-entry
x_refsource_OSVDB
18844
exploit
x_refsource_EXPLOIT-DB
81685
vdb-entry
x_refsource_OSVDB
53392
vdb-entry
x_refsource_BID
49029
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now