Proof-of-concept for CVE-2020-29666: directory listing vulnerability in Lan ATMService M3 ATM Monitoring System 6.1.0 that exposes log files containing user and developer cookie values.
[Suggested description]
In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory listing vulnerability, a remote attacker can view log files, located in /websocket/logs/, that contain a user's cookie values and the predefined developer's cookie value.
[Additional Information]
A letter was sent to the vendor about the vulnerability.
[VulnerabilityType Other]
CWE-548: Exposure of Information Through Directory Listing