VendorsTxjiaimcat4.4
Vulnerabilities

Txjia Imcat 4.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-20605
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.
Published 2018-12-30 · Modified
9.8EPSS 0.024
CVE-2018-20608
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
Published 2018-12-30 · Modified
7.5EPSS 0.121
CVE-2018-20606
imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.
Published 2018-12-30 · Modified
7.5EPSS 0.026
CVE-2018-20611
imcat 4.4 allow XSS via a crafted cookie to the root/tools/adbug/binfo.php?cookie URI.
Published 2018-12-30 · Modified
6.1EPSS 0.009
CVE-2018-20607
imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI.
Published 2018-12-30 · Modified
5.3EPSS 0.027
CVE-2018-20609
imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.
Published 2018-12-30 · Modified
5.3EPSS 0.027
CVE-2018-20610
imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter.
Published 2018-12-30 · Modified
4.9EPSS 0.019