Back to search
CVE-2020-36893
Published: Dec 10, 2025
Modified: Dec 11, 2025
PUBLISHED
Description
Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.
| Vendor | Product | Versions |
|---|---|---|
EIBIZ Co.,Ltd. | i-Media Server Digital Signage | affected 0 - <= 3.8.0 |
Weaknesses (CWE)
References
ExploitDB-48766
exploit
Zero Science Advisory ID ZSL-2020-5585
vendor-advisory
vdb-entry
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now