CVE-2020-36895
HIGHEIBIZ i-Media Server Digital Signage 3.8.0 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36895. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated configuration disclosure vulnerability in Eibiz i-Media Server Digital Signage <=3.8.0. By directly referencing the SiteConfig.properties file via an HTTP GET request, sensitive information such as credentials and database details can be exposed.
Description
EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative credentials, database connection details, and system configuration information.
Exploits (1)
This exploit demonstrates an unauthenticated configuration disclosure vulnerability in Eibiz i-Media Server Digital Signage <=3.8.0. By directly referencing the SiteConfig.properties file via an HTTP GET request, sensitive information such as credentials and database details can be exposed.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N