Medium severity5.3NVD Advisory· Published Jun 2, 2020· Updated Jun 17, 2026
CVE-2020-13227
CVE-2020-13227
Description
An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mechanism.
Affected products
3cpe:2.3:a:sysax:multi_server:6.90:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sysax:multi_server:6.90:*:*:*:*:*:*:*
- (no CPE)range: 6.90
- Sysax/Multi Serverdescription
Patches
Vulnerability mechanics
References
2- github.com/wrongsid3/Sysax-MultiServer-6.90-Multiple-Vulnerabilities/blob/master/README.mdnvdExploitThird Party Advisory
- pasteboard.co/J9eF12G.pngnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.