Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenEMR本地文件包含漏洞和命令注入漏洞
Vulnerability Description
OpenEMR中存在本地文件包含和命令注入漏洞,该漏洞源于对用户提供的数据未经充分过滤。攻击者可利用该漏洞通过以用户运行受影响应用程序的权限执行任意shell命令,获取潜在的敏感信息,或者在web服务器进程上下文中执行任意本地脚本。这可能允许攻击者操控应用程序和计算机,也可能执行其他的攻击。OpenEMR 4.1.0版本中存在该漏洞,其他版本中也可能存在该漏洞。
CVSS Information
N/A
Vulnerability Type
N/A