Security Advisory
CVE-2020-36893
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the servers root directory. Attackers can exploit the oldfile GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.