216.73.217.22

CVE-2020-36973

· Published 28/01/2026 18:16 · Modified 29/01/2026 16:31

Labels: CVE-2020-36973 2026-01-28CVE-2020-36973CWE-434[email protected]

Essential information

Published
28/01/2026 18:16
Modified
29/01/2026 16:31
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pdw / file browser cpe:2.3:a:pdw:file_browser:1.3:*:*:*:*:*:*:*

References