S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-35598 Scanner

CVE-2020-35598 scanner - Directory Traversal vulnerability in ACS Advanced Comment System

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-35598
7.5
CVSS

ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE: this might be the same as CVE-2009-4623

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ACS Advanced Comment System is a tool that website owners often use to manage comments on their site. The system allows them to review and approve or reject comments before they appear on the site, helping them maintain the quality of content on their pages. This system is essential for websites that encourage user-generated content, such as blogs, news sites, and forums.

One vulnerability that has been detected in the ACS Advanced Comment System is CVE-2020-35598. This vulnerability is a Directory Traversal issue that is based on the ACS_path parameter in the advanced_component_system/index.php file. If an attacker takes advantage of this vulnerability, they can access files or directories outside of the application's root directory, effectively gaining control over the application.

Exploiting this vulnerability can lead to multiple threats. It can allow an attacker to read, modify, or delete critical files on the web server. If the application is connected to a database, the attacker can also access sensitive data, including personal user information or administrative credentials. In the wrong hands, this vulnerability can cause long-term damage to the website's reputation, as well as lead to data breaches and loss of user trust.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. This platform offers users the ability to scan and check vulnerabilities in real-time, enabling them to identify and address issues before attackers can exploit them. By utilizing the platform, website owners can ensure the safety and security of their digital assets, keeping their users' data and critical files safe from unauthorized access.

 

REFERENCES

Solution Advice

There are several precautions one can take to protect against this vulnerability. Some of them include:

  • Applying the latest updates and security patches for ACS Advanced Comment System.
  • Implementing proper access controls and permissions for critical files and directories.
  • Using a Web Application Firewall (WAF) to detect and block malicious requests.
  • Limiting user input and sanitizing user inputs to prevent script injection attacks.
  • Running the system on a secure, isolated server and hardening the system configuration.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-35598 scanner - Directory Traversal vulnerability in ACS Advanced Comment System S4E