vendor:
MedDream PACS Server
by:
bzyo
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: MedDream PACS Server
Affected Version From: 6.8.3.751
Affected Version To: 6.8.3.751
Patch Exists: YES
Related CWE: N/A
CPE: a:softneta:meddream_pacs_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 2016
2020
MedDream PACS Server 6.8.3.751 – Remote Code Execution (Unauthenticated)
MedDream PACS Server 6.8.3.751 is vulnerable to Remote Code Execution. An unauthenticated attacker can exploit this vulnerability by creating a one line php shell to call commands, running the script on the attacking machine, and entering parameters such as IP, filename, and command. The attacker can then use varying time checks to call the command and view the output.
Mitigation:
Upgrade to the latest version of MedDream PACS Server.