CVE-2017-5569
Summary
| CVE | CVE-2017-5569 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-23 17:59:00 UTC |
| Updated | 2017-01-26 13:53:00 UTC |
| Description | An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile(). |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eclinicalworks | Patient Portal | 7.0 | All | All | All |
| Application | Eclinicalworks | Patient Portal | 7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| eClinicalWorks Patient Portal CVE-2017-5569 SQL Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| eClinicalWorks - Patient Portal v7.0 - Blind SQL Injection - pre-authentication - template.jsp · GitHub | MISC | gist.github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.