ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36897”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36897
Published
2025-12-10
CVSS:
9.3
ShadowTrackr CVSS:
8.1
Summary:
QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. Attackers can exploit the file upload functionality by using the 'remotePath' and 'fileToUpload' parameters to write and execute arbitrary system commands on the server.