vendor:
PACSOne Server
by:
Carlos Avila
7.5
CVSS
HIGH
Directory Traversal / Local File Inclusion
22
CWE
Product Name: PACSOne Server
Affected Version From: 6.6.2
Affected Version To: 6.6.2
Patch Exists: YES
Related CWE: N/A
CPE: pacsone:pacsone_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 / Debian Linux
2017
PACSOne Server 6.6.2 DICOM Web Viewer Directory Trasversal / Local File Inclusion
DICOM Web Viewer is a component written in PHP that is part of PacsOne software. In version 6.6.2, it is vulnerable to local file inclusion. This allows an attacker to read arbitrary files that the web user has access to. Admin credentials aren't required. The 'path' parameter via GET is vulnerable.
Mitigation:
Application inputs must be validated correctly.