---
id: CVE-2020-36893
title: Eibiz i-Media Server Digital Signage 3.8.0 Directory Traversal Vulnerability
summary: >-
  Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal
  vulnerability that allows unauthenticated remote attackers to access files
  outside the server's root directory. Attackers can exploit the 'oldfile' GET
  parameter t…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cvssSource: cna
cwe:
  - CWE-22
vendor: 'EIBIZ Co.,Ltd.'
product: i-Media Server Digital Signage
affected:
  - i-media_server_digital_signage <= 3.8.0
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-12-11T16:00:20.337529Z'
exploitAvailable: true
published: '2025-12-10'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:31.839Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2020-36893'
references:
  - url: 'https://www.exploit-db.com/exploits/48766'
    label: ExploitDB-48766
  - url: 'http://www.eibiz.co.th'
    label: 'EIBIZ Co.,Ltd. Product Web Page'
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5585.php'
    label: Zero Science Advisory ID ZSL-2020-5585
  - url: >-
      https://www.vulncheck.com/advisories/eibiz-i-media-server-digital-signage-directory-traversal-vulnerability
    label: >-
      VulnCheck Advisory: Eibiz i-Media Server Digital Signage 3.8.0 Directory
      Traversal Vulnerability
tags:
  - cve.org
  - exploit-available
epss: 0.01565
epssPercentile: 0.74393
ingestedAt: '2026-10-01T15:48:17.880Z'
---

## Overview

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.

## Affected

- `i-media_server_digital_signage <= 3.8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
