vendor:
Eibiz i-Media Server Digital Signage
by:
LiquidWorm
5.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Eibiz i-Media Server Digital Signage
Affected Version From:
Affected Version To: 3.8.2000
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows Server 2016, Windows Server 2012 R2, Windows Server 2008 R2, Apache Flex, Apache Tomcat/6.0.14, Apache-Coyote/1.1, BlazeDS Application
2020
Eibiz i-Media Server Digital Signage 3.8.0 – Directory Traversal
Eibiz i-Media Server Digital Signage 3.8.0 is affected by a directory traversal vulnerability. An unauthenticated remote attacker can exploit this to view the contents of files located outside of the server's root directory. The issue can be triggered through the 'oldfile' GET parameter.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability.