EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpage /showfile.php can be exploited to gain root access. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-01-07T13:55:26
Updated: 2024-08-03T16:45:50.882Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-3029
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-01-07T14:15:12.720
Modified: 2024-11-21T06:20:47.513
Link: CVE-2021-3029
Redhat
No data.