vendor:
i-Media Server Digital Signage
by:
LiquidWorm
7.5
CVSS
HIGH
Configuration Disclosure
200
CWE
Product Name: i-Media Server Digital Signage
Affected Version From: <=3.8.0
Affected Version To: <=3.8.0
Patch Exists: NO
Related CWE: N/A
CPE: a:eibiz:i-media_server_digital_signage
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2016, Windows Server 2012 R2, Windows Server 2008 R2, Apache Flex, Apache Tomcat/6.0.14, Apache-Coyote/1.1, BlazeDS Application
2020
Eibiz i-Media Server Digital Signage 3.8.0 – Configuration Disclosure
EIBIZ i-Media Server is vulnerable to unauthenticated configuration disclosure when direct object reference is made to the SiteConfig.properties file using an HTTP GET method. This will enable the attacker to disclose sensitive information and help her in authentication bypass, privilege escalation and/or full system access.
Mitigation:
Ensure that the configuration files are not accessible to unauthenticated users.