« Volver al listado

Rainbowfishsoftware

Rainbowfishsoftware Pacsone Server: vulnerabilidades y CVE

Rainbowfishsoftware Pacsone Server tiene 8 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses1
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2018-25124Alta (8.7)0.92%—10 nov 2025
PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within the web-based DICOM viewer component. Successful exploitation allows a remote unauthenticated…
CVE-2020-29166Alta (7.5)2.3%—3 feb 2021
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure.
CVE-2020-29165Crítica (9.8)1.7%—3 feb 2021
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges.
CVE-2020-29164Media (6.1)6.2%—3 feb 2021
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
CVE-2020-29163Alta (8.8)1.1%—3 feb 2021
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
CVE-2020-12870Crítica (9.8)1.6%—30 sept 2020
RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.
CVE-2020-12869Media (5.4)0.55%—30 sept 2020
RainbowFish PacsOne Server 6.8.4 allows XSS.
CVE-2020-12715Alta (8.8)1.2%—30 sept 2020
RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System1
  2. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.