.. / CVE-2012-0991

Exploit for OpenEMR 4.1 - Local File Inclusion (CVE-2012-0991)

Description:

Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.

Nuclei Template

View the template here CVE-2012-0991.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2012/CVE-2012-0991.yaml
Copy

References:

https://github.com/ARPSyndicate/kenzer-templates
https://www.exploit-db.com/exploits/36650
https://nvd.nist.gov/vuln/detail/CVE-2012-0991
http://www.open-emr.org/wiki/index.php/OpenEMR_Patches
https://exchange.xforce.ibmcloud.com/vulnerabilities/72914