Description
Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files including system configuration and password files.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Carlos Avila
References
www.exploit-db.com/exploits/45347 (ExploitDB-45347)
www.softneta.com/...ucts/meddream-pacs-server/downloads.html (Product Reference)
www.vulncheck.com/...pacs-server-premium-directory-traversal (VulnCheck Advisory: Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal)