First published: Thu Jan 07 2021(Updated: )
** UNSUPPORTED WHEN ASSIGNED ** EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpage /showfile.php can be exploited to gain root access. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Evolucare Ecs Imaging | <=6.21.5 | |
<=6.21.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3029 is an OS Command Injection vulnerability in EVOLUCARE ECSIMAGING (aka ECS Imaging) through version 6.21.5.
CVE-2021-3029 has a severity of 9.8 (Critical).
Evolucare Ecs Imaging version up to and including 6.21.5 is affected by CVE-2021-3029.
The vulnerability can be exploited by manipulating the "file" parameter on the /showfile.php webpage to gain root access.
As CVE-2021-3029 is unsupported, no official fix is available. It is recommended to upgrade to a supported version or apply appropriate mitigations.