ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

11 results for “CVE-2020-3697”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36973
Published
2026-01-28
CVSS:
8.7
ShadowTrackr CVSS:
6.3
Summary:
PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques.
CVE:
CVE-2020-36970
Published
2026-01-28
CVSS:
6.9
ShadowTrackr CVSS:
4.6
Summary:
PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.
CVE:
CVE-2020-36972
Published
2026-01-28
CVSS:
8.8
ShadowTrackr CVSS:
6.7
Summary:
SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information.
CVE:
CVE-2020-36971
Published
2026-01-28
CVSS:
8.4
ShadowTrackr CVSS:
5.7
Summary:
Nidesoft 3GP Video Converter 2.6.18 contains a local stack buffer overflow vulnerability in the license registration parameter. Attackers can craft a malicious payload and paste it into the 'License Code' field to execute arbitrary code on the system.
CVE:
CVE-2020-36978
Published
2026-01-27
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules.
CVE:
CVE-2020-36979
Published
2026-01-27
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.
CVE:
CVE-2020-36977
Published
2026-01-27
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to LocalSystem account.
CVE:
CVE-2020-36976
Published
2026-01-27
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup.
CVE:
CVE-2020-36975
Published
2026-01-27
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common Files\EPSON\EPW!3SSRP\E_S60RPB.EXE' to inject malicious executables and escalate privileges.
CVE:
CVE-2020-36974
Published
2026-01-27
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files\IDT\WDM\AESTSr64.exe' to inject malicious code that would execute during service startup or system reboot.
CVE:
CVE-2020-3697
Published
2021-12-20
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary: