i-media_server_digital_signage vulnerabilities
CVEs whose affected-version data names the i-media_server_digital_signage package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2020-36893High· 8.7PoCEibiz i-Media Server Digital Signage 3.8.0 Directory Traversal Vulnerability
Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter t…
CVE-2020-36894Critical· 9.3PoCEibiz i-Media Server Digital Signage 3.8.0 Unauthenticated User Creation Vulnerability
Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attackers can send crafted serialized objects…
CVE-2020-36892Critical· 9.3PoCEibiz i-Media Server Digital Signage 3.8.0 Unauthenticated Privilege Escalation
Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to eleva…
CVE-2020-36895High· 8.7PoCEIBIZ i-Media Server Digital Signage 3.8.0 Unauthenticated Configuration Disclosure
EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the Si…