First published: Tue Feb 07 2012(Updated: )
interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | =4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0992 is classified as a critical vulnerability due to its potential for remote command execution.
To fix CVE-2012-0992, update OpenEMR to a version later than 4.1.0 that addresses this security issue.
CVE-2012-0992 is a command injection vulnerability that allows remote authenticated users to execute arbitrary commands.
CVE-2012-0992 affects users of OpenEMR version 4.1.0 who have remote authenticated access.
CVE-2012-0992 specifically impacts systems running OpenEMR version 4.1.0.