
CVE-2020-37034 HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters.… https://www.cve.org/CVERecord?id=CVE-2020-37034
Post summary
The statement discloses that HelloWeb 2.0 suffers from an arbitrary file download flaw enabling remote attackers to retrieve system files by manipulating request parameters.
