RainbowfishsoftwareCVEs & Vulnerabilities
7 CVEs affecting Rainbowfishsoftware products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
Most Affected Products
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure.
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges.
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.
RainbowFish PacsOne Server 6.8.4 allows XSS.
RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.