esi_products CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

esi_products vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to esi_products, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2005-4029 WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out valid users via brute force methods. [email protected] 5.0 1.34% 2005-12-05 2026-06-16
CVE-2005-4002 WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation. [email protected] 4.0 0.90% 2005-12-05 2026-06-16
CVE-2005-2286 WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource. [email protected] 10.0 2.19% 2005-07-18 2026-06-16
CVE-2005-2285 WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Usernames, Passwords, Emergency information, medical information, and system configuration. [email protected] 5.0 1.30% 2005-07-18 2026-06-16
CVE-2005-2284 Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors. [email protected] 7.5 1.23% 2005-07-18 2026-06-16
CVE-2005-2283 WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file. [email protected] 2.1 0.47% 2005-07-18 2026-06-16
CVE-2005-2282 Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before 6.0.2 allow remote attackers to inject arbitrary web script and HTML via unknown vectors. [email protected] 4.3 1.01% 2005-07-18 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence