Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files including system configuration and password files.
History

Tue, 26 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files including system configuration and password files.
Title Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal
First Time appeared Softneta
Softneta meddream Pacs
Weaknesses CWE-22
CPEs cpe:2.3:a:softneta:meddream_pacs:6.7.1.1:*:*:*:*:*:*:*
Vendors & Products Softneta
Softneta meddream Pacs
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-05-25T14:15:18.585Z

Updated: 2026-05-26T15:21:31.622Z

Reserved: 2026-05-25T13:49:54.894Z

Link: CVE-2018-25374

cve-icon Vulnrichment

Updated: 2026-05-26T15:21:27.723Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T15:16:20.403

Modified: 2026-05-26T19:47:48.987

Link: CVE-2018-25374

cve-icon Redhat

No data.