module

OpenEMR 5.0.1 Patch 6 SQLi Dump

Disclosed
May 17, 2019
Created
Sep 12, 2019

Description

This module exploits a SQLi vulnerability found in
OpenEMR version 5.0.1 Patch 6 and lower. The
vulnerability allows the contents of the entire
database (with exception of log and task tables) to be
extracted.
This module saves each table as a `.csv` file in your
loot directory and has been tested with
OpenEMR 5.0.1 (3).

Author

Will Porter [email protected]

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/sqli/openemr/openemr_sqli_dump
msf auxiliary(openemr_sqli_dump) > show actions
...actions...
msf auxiliary(openemr_sqli_dump) > set ACTION < action-name >
msf auxiliary(openemr_sqli_dump) > show options
...show and set options...
msf auxiliary(openemr_sqli_dump) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.