Record summary

CVE-2020-36970 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.

Description

PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 28, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List5.6affected

Proofs of concept

1

Catalogued exploits

ExploitDBPMB 5.6 - 'chemin' Local File DisclosureExploitDB exploitby 41-trkNot analyzed1 file
ExploitDB

PoC details

References

5