Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-25374 1 Softneta 1 Meddream Pacs 2026-05-26 7.5 High
Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files including system configuration and password files.
CVE-2023-40150 1 Softneta 1 Meddream Pacs 2024-11-21 9.8 Critical
Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could result in unauthenticated remote code execution.0
CVE-2023-39227 1 Softneta 1 Meddream Pacs 2024-11-21 6.1 Medium
​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.