Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.103410
Category:Web application abuses
Title:OpenEMR 4.1.0 LFI and Command Injection Vulnerabilities
Summary:OpenEMR is prone to local file include (LFI) and command; injection vulnerabilities because it fails to properly sanitize user supplied input.
Description:Summary:
OpenEMR is prone to local file include (LFI) and command
injection vulnerabilities because it fails to properly sanitize user supplied input.

Vulnerability Impact:
A remote attacker can exploit these issues to execute arbitrary
shell commands with the privileges of the user running the application, obtain potentially
sensitive information, and execute arbitrary local scripts in the context of the Web server
process. This could allow the attacker to compromise the application and the computer. Other
attacks are also possible.

Affected Software/OS:
OpenEMR 4.1.0 is known to be vulnerable. Other versions may
also be affected.

Solution:
Updates are available. Please see the references for more
information.

CVSS Score:
8.5

CVSS Vector:
AV:N/AC:M/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-0991
BugTraq ID: 51788
http://www.securityfocus.com/bid/51788
Bugtraq: 20120201 Multiple vulnerabilities in OpenEMR (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2012-02/0004.html
https://www.htbridge.ch/advisory/HTB23069
http://osvdb.org/78727
http://osvdb.org/78728
http://osvdb.org/78729
http://osvdb.org/78730
http://secunia.com/advisories/47781
XForce ISS Database: openemr-formname-file-include(72914)
https://exchange.xforce.ibmcloud.com/vulnerabilities/72914
Common Vulnerability Exposure (CVE) ID: CVE-2012-0992
http://osvdb.org/78731
XForce ISS Database: openemr-faxdispatch-command-execution(72915)
https://exchange.xforce.ibmcloud.com/vulnerabilities/72915
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.