CVE-2020-37034 - HelloWeb 2.0 - Arbitrary File Download
CVE ID : CVE-2020-37034
Published : Jan. 30, 2026, 11:16 p.m. | 4 hours, 1 minute ago
Description : HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Jan. 30, 2026, 11:16 p.m. | 4 hours, 1 minute ago
Description : HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...