Vulnerabilities > CVE-2011-5161 - File-Upload vulnerability in Open-Emr Openemr 4.0.0/4.1.0/4.1.1

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
open-emr
exploit available

Summary

Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the patient directory under documents/. Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'

Vulnerable Configurations

Part Description Count
Application
Open-Emr
3

Exploit-Db

descriptionopenemr 4 - Multiple Vulnerabilities. CVE-2011-5160,CVE-2011-5161,CVE-2012-2115. Webapps exploit for php platform
fileexploits/php/webapps/18274.txt
idEDB-ID:18274
last seen2016-02-02
modified2011-12-25
platformphp
port
published2011-12-25
reporterLevel
sourcehttps://www.exploit-db.com/download/18274/
titleopenemr 4 - Multiple Vulnerabilities
typewebapps