CVE-2020-36893
HIGHEibiz i-Media Server Digital Signage 3.8.0 - Path Traversal
Title source: llmDescription
Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.
Exploits (1)
References (4)
Scores
CVSS v3
7.5
EPSS
0.1000
EPSS Percentile
93.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
eibiz/i-media_server_digital_signage
3.8.0
Published
Dec 10, 2025
Tracked Since
Feb 18, 2026