CVE-2012-6567
https://notcve.org/view.php?id=CVE-2012-6567
REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule. REDCap anterior a v4.14.0 permite a usuarios remotos autenticados ejecutar código arbitrario a través de metacaracteres de shell en la lógica de una regla personalizada • http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf • CWE-20: Improper Input Validation •
CVE-2013-4609
https://notcve.org/view.php?id=CVE-2013-4609
REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call. REDCap anterior a v5.0.4 y v5.1.x anterior a v5.1.3 no rechaza cierta sintaxis no documentada dentro de la lógica de bifurcación y cálculos, lo que permite a usuarios autenticados remotamente evitar las restricciones de acceso establecidas a través de (1) el Online Designer o (2) el Data Dictionary Upload, como se demostró por una llamada eval. • http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2013-4612
https://notcve.org/view.php?id=CVE-2013-4612
Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different modules. Múltiples vulnerabilidades de cross-site scripting (XSS) en REDCap anterior a v5.1.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados implicando diferentes módulos. • http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-6565
https://notcve.org/view.php?id=CVE-2012-6565
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary web script or HTML via uppercase characters in JavaScript events within user-defined labels. Vulnerabilidad Cross-site scripting (XSS) en REDCap anterior a v4.14.3 permite a los usuarios remotos autenticados inyectar secuencias de comandos web o HTML a través de caracteres mayúsculas en los eventos de JavaScript dentro de las etiquetas definidas por el usuario. • http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-4611
https://notcve.org/view.php?id=CVE-2013-4611
Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Survey Participants page. Múltiples vulnerabilidades no especificadas en REDCap anterior a v5.1.1 permite a atacantes remotos tener un impacto no determinado a través de vectores que implican (1) la pagina de Online Designer o (2) la pagina de Manage Survey Participants. • http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf •