CVE-2020-36970
HIGHPMB Services 5.6 - Path Traversal and Arbitrary File Read via getgif.php chemin Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36970. PoCs published by 41-trk.
AI-analyzed exploit summary This exploit demonstrates a local file disclosure vulnerability in PMB 5.6 due to unsanitized input in the 'chemin' parameter of getgif.php. The PoC shows how an attacker can read arbitrary files by traversing directories.
Description
PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.
Exploits (1)
This exploit demonstrates a local file disclosure vulnerability in PMB 5.6 due to unsanitized input in the 'chemin' parameter of getgif.php. The PoC shows how an attacker can read arbitrary files by traversing directories.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H