Software Download Repositoryproduct
http://forge.sigb.net/redmine/projects/pmb/files CVE-2020-36970
MEDIUM
PMB 5.6 - 'chemin' Local File Disclosure
Record summary
CVE-2020-36970 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 28, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PMB ServicesBrowse PMB Services / PMB Services | CVE List | 5.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPMB 5.6 - 'chemin' Local File DisclosureExploitDB exploitby 41-trkNot analyzed1 file
References
5Vendor Homepageproduct
http://www.sigb.net/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36970 ExploitDB-49054exploit
https://www.exploit-db.com/exploits/49054 VulnCheck Advisory: PMB 5.6 - 'chemin' Local File DisclosureThird-party advisory
https://www.vulncheck.com/advisories/pmb-chemin-local-file-disclosure