Vulnerability Description
PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/michalc/PDW-File-Browser
- https://www.exploit-db.com/exploits/48987
- https://www.vulncheck.com/advisories/pdw-file-browser-remote-code-execution
- https://www.exploit-db.com/exploits/48987
FAQ
What is CVE-2020-36973?
CVE-2020-36973 is a vulnerability with a CVSS score of 6.5 (MEDIUM). PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt w...
How severe is CVE-2020-36973?
CVE-2020-36973 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36973?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.