QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. Attackers can exploit the file upload functionality by using the 'remotePath' and 'fileToUpload' parameters to write and execute arbitrary system commands on the server.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. Attackers can exploit the file upload functionality by using the 'remotePath' and 'fileToUpload' parameters to write and execute arbitrary system commands on the server. | |
| Title | QiHang Media Web Digital Signage 3.0.9 Unauthenticated Remote Code Execution | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-10T21:02:56.142Z
Updated: 2025-12-11T18:52:59.886Z
Reserved: 2025-12-09T11:46:53.452Z
Link: CVE-2020-36897
Updated: 2025-12-11T15:53:53.113Z
Status : Received
Published: 2025-12-10T21:16:02.210
Modified: 2025-12-11T19:15:49.827
Link: CVE-2020-36897
No data.