Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files including system configuration and password files.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files including system configuration and password files. | |
| Title | Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal | |
| First Time appeared |
Softneta
Softneta meddream Pacs |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:softneta:meddream_pacs:6.7.1.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Softneta
Softneta meddream Pacs |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-25T14:15:18.585Z
Reserved: 2026-05-25T13:49:54.894Z
Link: CVE-2018-25374
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T15:30:06Z
Weaknesses