Vulnerabilities
16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-35370 +1 in the same advisory: …35369 | An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function. An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2021-36444 +1 in the same advisory: …36443 | Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation on the add Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation on the add administrator page. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-22120 | A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code. A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2020-20392 | SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php. SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2020-23520 | imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality. imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality. NVD description · AI analysis pending | 7.2 | 2% | PoC |
| — | |
| CVE-2019-14968 | An issue was discovered in imcat 4.9. An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-8436 | imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter. imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2018-20605 | imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file. imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — |