Latest Vulnerabilities and Exploits
CVE ID:
CVE-2021-3029Details:
** UNSUPPORTED WHEN ASSIGNED ** EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpage /showfile.php can be exploited to gain root access. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.References:
:https://shoxxdj.fr/ecsimaging-os-injection-cve-2021-3029/:https://www.evolucare.com
ZeroDayLab Assigned Tags:
PRIVILEGE ESCALATIONINJECTION ATTACK
ROOT ACCESS