PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
low·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2012-0991 Scanner

CVE-2012-0991 scanner - Directory Traversal vulnerability in OpenEMR

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2012-0991
3.5
CVSS

Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

OpenEMR is a robust and versatile electronic health records (EHR) software that is widely used by healthcare providers worldwide. It is designed to assist healthcare providers in managing their patients’ medical records and workflow processes. OpenEMR is a free and open source health IT solution that offers features such as patient scheduling, demographics, medical billing, clinical decision support, and electronic prescribing.

The CVE-2012-0991 vulnerability is a directory traversal security flaw that was detected in OpenEMR 4.1.0. It is caused by improper input validation and allows remote authenticated users to access arbitrary files by using a ".." (dot dot) in the formname parameter of contrib/acog/print_form.php or several files in interface/patient_file/encounter, including load_form.php, view_form.php, and trend_form.php. 

When exploited, this vulnerability could allow an attacker to read sensitive data such as PHI (protected health information) of patients, thereby putting confidential medical records at risk. An attacker could also execute arbitrary code, modify files, or even delete critical system files, leading to a potential breach of the organization’s data and systems.

At s4e.io, we have a comprehensive suite of pro security features that can help identify and mitigate security risks in your digital assets. Our platform provides automated vulnerability scanning, network discovery, and real-time threat notifications, among other features. By leveraging our platform, you can easily and quickly learn about vulnerabilities in your digital assets and keep your organization’s data and systems secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to take the following precautions: 

  • Apply security patches and software updates as soon as they become available.
  • Use strong authentication mechanisms such as multi-factor authentication.
  • Implement role-based access control (RBAC) to ensure that only authorized users have privileges to access sensitive data.
  • Disable unnecessary services and ports, and limit access to critical resources.
  • Conduct regular security assessments and penetration testing to identify potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2012-0991 scanner - Directory Traversal vulnerability in OpenEMR | S4E