VYPR

Cardio Server

by Epiphanyhealthdata

CVEs (2)

  • CVE-2015-6538CriDec 27, 2015
    risk 0.64cvss 9.8epss 0.02

    The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.

  • CVE-2015-6537CriDec 27, 2015
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in the login page in Epiphany Cardio Server 3.3 allows remote attackers to execute arbitrary SQL commands via a crafted URL.