ZeroHour

Vulnerabilities

16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35370
+1 in the same advisory: …35369
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.

An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • txjia imcat
CVE-2021-36444
+1 in the same advisory: …36443
Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation on the add

Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation on the add administrator page.

NVD description · AI analysis pending
8.8<1% PoC
  • txjia imcat
CVE-2020-22120
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.

A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.

NVD description · AI analysis pending
8.82% PoC
  • txjia imcat
CVE-2020-20392
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.

SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.

NVD description · AI analysis pending
9.81% PoC
  • txjia imcat
CVE-2020-23520
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.

imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.

NVD description · AI analysis pending
7.22% PoC
  • txjia imcat
CVE-2019-14968
An issue was discovered in imcat 4.9.

An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.

NVD description · AI analysis pending
9.82% PoC
  • txjia imcat
CVE-2019-8436
imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.

imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • txjia imcat
CVE-2018-20605
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.

imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • txjia imcat