nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37034 CVE-2020-37034
HIGH
HelloWeb 2.0 - Arbitrary File Download
Record summary
CVE-2020-37034 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 2, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
HelloWebBrowse HELLOWEB / HelloWeb | CVE List | 2.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBHelloWeb 2.0 - Arbitrary File DownloadExploitDB exploitby bRpsdNot analyzed1 file
References
4Archived HelloWeb Vendor Homepageproduct
https://web.archive.org/web/20190109182037/https://helloweb.co.kr ExploitDB-48659exploit
https://www.exploit-db.com/exploits/48659 VulnCheck Advisory: HelloWeb 2.0 - Arbitrary File DownloadThird-party advisory
https://www.vulncheck.com/advisories/helloweb-arbitrary-file-download