OpenEMR.ajax_download.php.Directory.Traversal
Description
This indicates an attack attempt to exploit a Directory Traversal Vulnerability in OpenEMR Development Team OpenEMR.
A remote, authenticated attacker could exploit this vulnerability by sending a crafted HTTP request to a vulnerable server. Successful exploitation could result in arbitrary file read or deletion on the target server under the privilege of web server.
Affected Products
OpenEMR Development Team OpenEMR 5.0.1 and earlier
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://www.open-emr.org/wiki/index.php/OpenEMR_Downloads
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2021-03-09 | 18.032 | |
2019-10-22 | 14.708 | Default_action:pass:drop |
2019-09-26 | 14.695 |