Vulnerabilities > ESI Products

DATE CVE VULNERABILITY TITLE RISK
2005-12-05 CVE-2005-4029 Remote Security vulnerability in WebEOC
WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out valid users via brute force methods.
network
low complexity
esi-products
5.0
2005-12-05 CVE-2005-4002 Remote Security vulnerability in WebEOC
WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.
network
low complexity
esi-products
4.0
2005-07-18 CVE-2005-2286 Unspecified vulnerability in ESI products Webeoc
WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
network
low complexity
esi-products
critical
10.0
2005-07-18 CVE-2005-2285 Unspecified vulnerability in ESI products Webeoc
WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Usernames, Passwords, Emergency information, medical information, and system configuration.
network
low complexity
esi-products
5.0
2005-07-18 CVE-2005-2284 Unspecified vulnerability in ESI products Webeoc
Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors.
network
low complexity
esi-products
7.5
2005-07-18 CVE-2005-2283 Unspecified vulnerability in ESI products Webeoc
WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file.
local
low complexity
esi-products
2.1
2005-07-18 CVE-2005-2282 Unspecified vulnerability in ESI products Webeoc 6.0.2
Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before 6.0.2 allow remote attackers to inject arbitrary web script and HTML via unknown vectors.
network
esi-products
4.3