vendor:
Dicoogle PACS
by:
Carlos Avila
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Dicoogle PACS
Affected Version From: Dicoogle PACS 2.5.0
Affected Version To: Dicoogle PACS 2.5.0
Patch Exists: NO
Related CWE:
CPE: a:dicoogle:dicoogle_pacs:2.5.0
Platforms Tested: Windows 2012 R2
2018
Dicoogle PACS 2.5.0 – Directory Traversal
Dicoogle PACS 2.5.0 is vulnerable to local file inclusion, allowing an attacker to read arbitrary files that the web user has access to. Admin credentials are not required. The 'UID' parameter via GET is vulnerable.
Mitigation:
Update to a patched version of Dicoogle PACS or apply appropriate security measures to prevent directory traversal attacks.