CVE-2020-36893
HIGHEibiz i-Media Server Digital Signage 3.8.0 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36893. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Eibiz i-Media Server Digital Signage 3.8.0. An unauthenticated attacker can use the 'oldfile' GET parameter to read arbitrary files outside the server's root directory.
Description
Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in Eibiz i-Media Server Digital Signage 3.8.0. An unauthenticated attacker can use the 'oldfile' GET parameter to read arbitrary files outside the server's root directory.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N