HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.
History

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Helloweb
Helloweb helloweb
Vendors & Products Helloweb
Helloweb helloweb

Mon, 02 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 22:30:00 +0000

Type Values Removed Values Added
Description HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.
Title HelloWeb 2.0 - Arbitrary File Download
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-30T22:07:12.857Z

Updated: 2026-02-02T20:13:25.857Z

Reserved: 2026-01-28T18:18:30.523Z

Link: CVE-2020-37034

cve-icon Vulnrichment

Updated: 2026-02-02T20:13:21.938Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-30T23:16:08.713

Modified: 2026-02-03T16:44:36.630

Link: CVE-2020-37034

cve-icon Redhat

No data.