CVE-2020-36893 PUBLISHED

Eibiz i-Media Server Digital Signage 3.8.0 Directory Traversal Vulnerability

Assigner: VulnCheck
Reserved: 09.12.2025 Published: 10.12.2025 Updated: 11.12.2025

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor EIBIZ Co.,Ltd.
Product i-Media Server Digital Signage
Versions Default: unaffected
  • affected from 0 to 3.8.0 (incl.)

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE