Description

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.

INFO

Published Date :

2025-12-10T20:52:52.187Z

Last Modified :

2025-12-11T18:53:24.647Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2020-36893 vulnerability.

Vendors Products
Eibiz
  • I-media Server Digital Signage
Microsoft
  • Windows

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability