← Back

Txjia

txjia

16 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Imcat
imcat

CVEs (16)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Txjia
1Imcat
Mar 12, 2025
Feb 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
1Txjia
1Imcat
Mar 12, 2025
Feb 24, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Arbitrary File Read vulnerability found in Peacexie ImCat v.5.2 fixed in v.5.4 allows attackers to obtain sensitive information via the filtering_get_contents function.
1Txjia
1Imcat
Mar 26, 2025
Feb 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation on the add administrator page.
1Txjia
1Imcat
Mar 26, 2025
Feb 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification.
1Txjia
1Imcat
Nov 21, 2024
Aug 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.
1Txjia
1Imcat
Nov 21, 2024
Jun 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
1Txjia
1Imcat
Nov 21, 2024
Dec 9, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.
1Txjia
1Imcat
Nov 21, 2024
Aug 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
1Txjia
1Imcat
Nov 21, 2024
Feb 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
imcat 4.4 allow XSS via a crafted cookie to the root/tools/adbug/binfo.php?cookie URI.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.