PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.
Metrics
Affected Vendors & Products
References
History
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pmb Services
Pmb Services pmb Services |
|
| Vendors & Products |
Pmb Services
Pmb Services pmb Services |
Wed, 28 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint. | |
| Title | PMB 5.6 - 'chemin' Local File Disclosure | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-28T17:35:11.195Z
Updated: 2026-01-28T21:29:26.284Z
Reserved: 2026-01-27T15:47:07.998Z
Link: CVE-2020-36970
Updated: 2026-01-28T18:58:48.019Z
Status : Awaiting Analysis
Published: 2026-01-28T18:16:47.487
Modified: 2026-01-29T16:31:00.867
Link: CVE-2020-36970
No data.