Product
txjia imcat
16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-35370
CVE-2021-35369
CVE-2021-36444
CVE-2021-36443
CVE-2020-22120
CVE-2020-20392
CVE-2020-23520
CVE-2019-14968
CVE-2019-8436
CVE-2018-20611
CVE-2018-20610
CVE-2018-20609
CVE-2018-20608
CVE-2018-20607
CVE-2018-20606
CVE-2018-20605
all versions
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
all versions
Arbitrary File Read vulnerability found in Peacexie ImCat v.5.2 fixed in v.5.4 allows attackers to obtain sensitive information vi
all versions
Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one ti
all versions
Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification
all versions
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attacker
all versions
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
all versions
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.
all versions
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
all versions
imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.
all versions
imcat 4.4 allow XSS via a crafted cookie to the root/tools/adbug/binfo.php?cookie URI.
all versions
imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter.
all versions
imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI
all versions
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
all versions
imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI.
all versions
imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.
all versions
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.