OpenEMR Multiple SQL Injection and Arbitrary File Upload Vulnerabilities
BID:62365
Info
OpenEMR Multiple SQL Injection and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 62365 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2013 12:00AM |
| Updated: | Mar 19 2015 08:17AM |
| Credit: | xistence |
| Vulnerable: |
OpenEMR OpenEMR 4.1 OpenEMR OpenEMR 4.0 |
| Not Vulnerable: | |
Discussion
OpenEMR Multiple SQL Injection and Arbitrary File Upload Vulnerabilities
OpenEMR is prone to multiple SQL-injection vulnerabilities and an arbitrary file-upload vulnerability.
Exploiting these issues could allow an attacker to upload arbitrary files, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OpenEMR is prone to multiple SQL-injection vulnerabilities and an arbitrary file-upload vulnerability.
Exploiting these issues could allow an attacker to upload arbitrary files, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
OpenEMR Multiple SQL Injection and Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues using a web browser.
The following example data is available:
An attacker can exploit these issues using a web browser.
The following example data is available:
Solution / Fix
OpenEMR Multiple SQL Injection and Arbitrary File Upload Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
OpenEMR Multiple SQL Injection and Arbitrary File Upload Vulnerabilities
References:
References:
- OpenEMR Homepage (OpenEMR)