CVE-2020-36893

Source
https://cve.org/CVERecord?id=CVE-2020-36893
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36893.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-36893
Published
2025-12-10T21:16:01.580Z
Modified
2026-03-15T22:36:09.061524Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.8.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36893.json"