PT-2007-2105 · Openemr · Openemr
Published
2007-02-01
·
Updated
2018-10-16
·
CVE-2007-0649
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:H/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions 2.8.2 and earlier
Description
The issue allows remote attackers to overwrite arbitrary program variables, leading to unauthorized activities. This can be exploited to conduct remote file inclusion attacks via the
srcdir parameter in "custom/import xml.php" or cross-site scripting (XSS) attacks via the rootdir parameter in "interface/login/login frame.php". The vulnerability is associated with extract operations on the POST and GET superglobal arrays.Recommendations
For OpenEMR versions 2.8.2 and earlier, update to a version that fixes the variable overwrite vulnerability to prevent remote attackers from overwriting arbitrary program variables.
As a temporary workaround, consider restricting access to the
custom/import xml.php and interface/login/login frame.php files to minimize the risk of exploitation.
Avoid using the srcdir and rootdir parameters in the affected files until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr