nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3118 CVE-2021-3118
CRITICAL
ECSIMAGING PACS 6.21.5 - SQL injection
Record summary
CVE-2021-3118 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBECSIMAGING PACS 6.21.5 - SQL injectionExploitDB exploitby shoxxdjNot analyzed1 file
References
2exploit-db.com
https://www.exploit-db.com/exploits/49392