txjia records
16 published records for vendor txjia.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-20605No exploit | imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.txjia · imcat · CWE-94 | Critical9.8 | — | 2.4% | Dec 30, 2018 |
39Monitor | CVE-2019-14968No exploit | An issue was discovered in imcat 4.9.txjia · imcat · CWE-89 | Critical9.8 | — | 1.5% | Aug 12, 2019 |
39Monitor | CVE-2020-20392No exploit | SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.txjia · imcat · CWE-89 | Critical9.8 | — | 1.4% | Jun 23, 2021 |
39Monitor | CVE-2021-35370No exploit | An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.txjia · imcat · CWE-20 | Critical9.8 | — | 1.0% | Feb 24, 2023 |
36Monitor | CVE-2020-22120No exploit | A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to executxjia · imcat · CWE-94 | High8.8 | — | 2.5% | Aug 18, 2021 |
35Monitor | CVE-2021-36444No exploit | Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token gtxjia · imcat · CWE-352 | High8.8 | — | 0.6% | Feb 3, 2023 |
35Monitor | CVE-2021-36443No exploit | Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification.txjia · imcat · CWE-352 | High8.8 | — | 0.6% | Feb 3, 2023 |
34Monitor | CVE-2018-20608Proof of concept | imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.txjia · imcat · CWE-200 | High7.5 | — | 12.1% | Dec 30, 2018 |
31Monitor | CVE-2018-20606No exploit | imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.txjia · imcat · CWE-200 | High7.5 | — | 2.6% | Dec 30, 2018 |
29Monitor | CVE-2020-23520No exploit | imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.txjia · imcat · CWE-434 | High7.2 | — | 2.3% | Dec 9, 2020 |
26Monitor | CVE-2021-35369No exploit | Arbitrary File Read vulnerability found in Peacexie ImCat v.5.2 fixed in v.5.4 allows attackers to obtain sensitive information via the filttxjia · imcat · CWE-125 | Medium6.5 | — | 0.6% | Feb 24, 2023 |
24Monitor | CVE-2018-20611No exploit | imcat 4.4 allow XSS via a crafted cookie to the root/tools/adbug/binfo.php?cookie URI.txjia · imcat · CWE-79 | Medium6.1 | — | 0.9% | Dec 30, 2018 |
22Monitor | CVE-2018-20609No exploit | imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.txjia · imcat · CWE-200 | Medium5.3 | — | 2.7% | Dec 30, 2018 |
22Monitor | CVE-2018-20607No exploit | imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI.txjia · imcat · CWE-200 | Medium5.3 | — | 2.7% | Dec 30, 2018 |
21Monitor | CVE-2019-8436No exploit | imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.txjia · imcat · CWE-79 | Medium5.4 | — | 0.6% | Feb 17, 2019 |
20Monitor | CVE-2018-20610No exploit | imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter.txjia · imcat · CWE-22 | Medium4.9 | — | 1.9% | Dec 30, 2018 |
- CVE-2018-2060540Plan
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.
CriticalCVSS 9.8No exploitEPSS 2%txjia · imcatDec 30, 2018
- CVE-2019-1496839Monitor
An issue was discovered in imcat 4.9.
CriticalCVSS 9.8No exploitEPSS 2%txjia · imcatAug 12, 2019
- CVE-2020-2039239Monitor
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
CriticalCVSS 9.8No exploitEPSS 1%txjia · imcatJun 23, 2021
- CVE-2021-3537039Monitor
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
CriticalCVSS 9.8No exploitEPSS 1%txjia · imcatFeb 24, 2023
- CVE-2020-2212036Monitor
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execu
HighCVSS 8.8No exploitEPSS 2%txjia · imcatAug 18, 2021
- CVE-2021-3644435Monitor
Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token g
HighCVSS 8.8No exploitEPSS 1%txjia · imcatFeb 3, 2023
- CVE-2021-3644335Monitor
Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification.
HighCVSS 8.8No exploitEPSS 1%txjia · imcatFeb 3, 2023
- CVE-2018-2060834Monitor
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
HighCVSS 7.5Proof of conceptEPSS 12%txjia · imcatDec 30, 2018
- CVE-2018-2060631Monitor
imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.
HighCVSS 7.5No exploitEPSS 3%txjia · imcatDec 30, 2018
- CVE-2020-2352029Monitor
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.
HighCVSS 7.2No exploitEPSS 2%txjia · imcatDec 9, 2020
- CVE-2021-3536926Monitor
Arbitrary File Read vulnerability found in Peacexie ImCat v.5.2 fixed in v.5.4 allows attackers to obtain sensitive information via the filt
MediumCVSS 6.5No exploitEPSS 1%txjia · imcatFeb 24, 2023
- CVE-2018-2061124Monitor
imcat 4.4 allow XSS via a crafted cookie to the root/tools/adbug/binfo.php?cookie URI.
MediumCVSS 6.1No exploitEPSS 1%txjia · imcatDec 30, 2018
- CVE-2018-2060922Monitor
imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.
MediumCVSS 5.3No exploitEPSS 3%txjia · imcatDec 30, 2018
- CVE-2018-2060722Monitor
imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI.
MediumCVSS 5.3No exploitEPSS 3%txjia · imcatDec 30, 2018
- CVE-2019-843621Monitor
imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.
MediumCVSS 5.4No exploitEPSS 1%txjia · imcatFeb 17, 2019
- CVE-2018-2061020Monitor
imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter.
MediumCVSS 4.9No exploitEPSS 2%txjia · imcatDec 30, 2018