Junglewise Threat Intelligence

CVE-2018-25374: Softneta MedDream PACS Server Premium directory traversal in nocache.php

CVE-2018-25374 · Severity: high · CVSS 7.5 · Published 2026-05-25

Executive brief

Softneta MedDream PACS Server Premium, a system used by healthcare providers to store and manage medical imaging like X-rays and MRIs, contains a security flaw. An unauthenticated attacker can exploit this to remotely access sensitive files on the server, including system configurations and user passwords. This could lead to the exposure of patient data or full unauthorized access to the medical imaging network.

Technical details

A directory traversal vulnerability exists in Softneta MedDream PACS Server Premium version 6.7.1.1 and potentially earlier versions. The flaw is located in the 'nocache.php' component, which fails to properly sanitize the 'path' input parameter. An unauthenticated remote attacker can use encoded backslash sequences (e.g., %5c%2e%2e%5c) to escape the intended web directory. This allows for the retrieval of arbitrary files from the underlying Windows host, including sensitive configuration files and 'passwords.txt', which may facilitate further authentication bypass or system compromise. While the vendor recommends keeping systems updated and isolated from the internet, users should ensure they are running a version later than 6.7.1.1.

Affected products

  • Softneta MedDream PACS Server Premium 6.7.1.1 and earlier

Timeline

  • 2018-05-23: disclosed: Initial discovery by researcher
  • 2018-09-07: other: Exploit published on Exploit-DB
  • 2026-05-25: advisory: CVE formally published/updated via VulnCheck

References