Record summary

CVE-2018-20608 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHImcat 4.4 - Phpinfo ConfigurationCVSS 7.5

Imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.

Impact

The vulnerability can lead to the exposure of sensitive information, such as server configuration details.

Remediation

Update Imcat to the latest version or apply the necessary patches to fix the Phpinfo Configuration vulnerability.

WeaknessesCWE-200
Authorsritikchaddha
Template tagscve2018cveimcatphpinfoconfigtxjiavuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:txjia:imcat:4.4:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2