This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:openemr:openemr |
| Detail | |||
|---|---|---|---|
| Vendor | Openemr | First view | 2006-06-09 |
| Product | Openemr | Last view | 2012-02-07 |
| Version | Type | Application | |
| Edition | |||
| Language | |||
| Update | |||
Activity : Yearly
COMMON PLATFORM ENUMERATION : Repartition per Version
| CPE Name | Affected CVE |
|---|---|
| cpe:/a:openemr:openemr:4.1.0 | 2 |
| cpe:/a:openemr:openemr:2.8.2 | 1 |
| cpe:/a:openemr:openemr:2.8.1 | 3 |
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 8.5 | 2012-02-07 | CVE-2012-0992 | Network | Medium | Requires ... | |
| 3.5 | 2012-02-07 | CVE-2012-0991 | Network | Medium | Requires ... | |
| 4.3 | 2007-01-31 | CVE-2007-0649 | Network | High | Requires ... | |
| 6.8 | 2006-11-08 | CVE-2006-5811 | Network | Medium | None Requ... | |
| 7.5 | 2006-11-08 | CVE-2006-5795 | Network | Low | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 6.8 | 2006-06-09 | CVE-2006-2929 | Network | Medium | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 33% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
| 33% (1) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
| 33% (1) | CWE-20 | Improper Input Validation |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 33609 | OpenEMR interface/login/login_frame.php rootdir Parameter XSS |
| 33603 | OpenEMR import_xml.php srcdir Parameter Remote File Inclusion |
| 30613 | OpenEMR translation.inc.php GLOBALS[srcdir] Parameter Remote File Inclusion |
| 30612 | OpenEMR import_xml.php srcdir Parameter Remote File Inclusion |
| 30611 | OpenEMR facility_admin.php srcdir Parameter Remote File Inclusion |
| id | Description |
|---|---|
| 30610 | OpenEMR user_info.php srcdir Parameter Remote File Inclusion |
| 30609 | OpenEMR usergroup_admin.php srcdir Parameter Remote File Inclusion |
| 30608 | OpenEMR facility_admin.php srcdir Parameter Remote File Inclusion |
| 30607 | OpenEMR front_receipts_report.php srcdir Parameter Remote File Inclusion |
| 30606 | OpenEMR players_report.php srcdir Parameter Remote File Inclusion |
| 30605 | OpenEMR custom_report_range.php srcdir Parameter Remote File Inclusion |
| 30604 | OpenEMR logout.php srcdir Parameter Remote File Inclusion |
| 30603 | OpenEMR ins_search.php srcdir Parameter Remote File Inclusion |
| 30602 | OpenEMR new_patient_save.php srcdir Parameter Remote File Inclusion |
| 30601 | OpenEMR main.php srcdir Parameter Remote File Inclusion |
| 30600 | OpenEMR main_info.php srcdir Parameter Remote File Inclusion |
| 30599 | OpenEMR interface/login/login.php srcdir Parameter Remote File Inclusion |
| 30598 | OpenEMR batchcom.php srcdir Parameter Remote File Inclusion |
| 30597 | OpenEMR login.php srcdir Parameter Remote File Inclusion |
| 30596 | OpenEMR print_billing_report.php srcdir Parameter Remote File Inclusion |
| 30595 | OpenEMR billing_report_xml.php srcdir Parameter Remote File Inclusion |
| 30594 | OpenEMR billing_report.php srcdir Parameter Remote File Inclusion |
| 30593 | OpenEMR billing_process.php srcdir Parameter Remote File Inclusion |
| 26231 | OpenEMR C_FormEvaluation.class.php fileroot Parameter Remote File Inclusion |
Milw0rm Exploits
| id | Description |
|---|---|
| 2006-11-06 | OpenEMR <= 2.8.1 (srcdir) Multiple Remote File Inclusion Vulnerabilities |
| 2006-06-07 | OpenEMR <= 2.8.1 (fileroot) Remote File Include Vulnerability |









