Directory Traversal Vulnerability in Softneta MedDream PACS Server Premium
CVE-2018-25374
Key Information:
- Vendor
Softneta
- Vendor
- CVE Published:
- 25 May 2026
Badges
What is CVE-2018-25374?
The Softneta MedDream PACS Server Premium version 6.7.1.1 is susceptible to a directory traversal vulnerability. This flaw allows attackers to exploit the path parameter by sending specially crafted requests to nocache.php, which may include encoded backslash sequences. Unauthenticated attackers can leverage this vulnerability to traverse directories and gain access to sensitive files, such as system configurations and password files, posing significant risks to data security.
Affected Version(s)
MedDream PACS Server Premium 6.7.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
