EIP-2026-110444
PRE-CVEPACSOne Server 6.6.2 DICOM Web Viewer - SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110444. PoCs published by Carlos Avila.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in PACSOne Server 6.6.2's DICOM Web Viewer. The 'username' and 'email' parameters in the POST request to '/pacs/userSignup.php' are vulnerable, allowing unauthenticated remote attackers to execute arbitrary SQL commands.
Description
PACSOne Server 6.6.2 DICOM Web Viewer - SQL Injection
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in PACSOne Server 6.6.2's DICOM Web Viewer. The 'username' and 'email' parameters in the POST request to '/pacs/userSignup.php' are vulnerable, allowing unauthenticated remote attackers to execute arbitrary SQL commands.