World cyber news is online news media.we bought daily hottest news occuring in the world related to cyber.. We propogate news specially related to hacking, technology updates , cyber world updates....

Wednesday, April 20, 2011

OpenEMR Local File Include and Cross-Site Scripting Vulnerabilities

12:46 AM Posted by Administrator , ,

OpenEMR is prone to a local file-include vulnerability and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerability using directory-traversal strings to view and execute local files within the context of the affected application. Information harvested may aid in further attacks.
The attacker may leverage the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Vendor:
http://www.sourceforge.net/projects/openemr/
http://www.oemr.org/
OpenEMR 4.0.0 is vulnerable; other versions may also be affected.
Exploit:
Local file include:

http://www.example.com/openemr-4.0.0/index.php?site=..%2f..%2f..
%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini

Cross-site scripting:

http://www.example.com/openemr-4.0.0/setup.php?site=%3Cscript%3Ealert
(0)%3C/script%3E

http://www.example.com/openemr-4.0.0/gacl/admin/object_search.php?
object_type=&action