github.com
https://github.com/AvaterXXX/CVEs/blob/master/imcat.md CVE-2018-20608
HIGHNuclei
Imcat 4.4 - Phpinfo Configuration
Record summary
CVE-2018-20608 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHImcat 4.4 - Phpinfo ConfigurationCVSS 7.5
Imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
Impact
The vulnerability can lead to the exposure of sensitive information, such as server configuration details.
Remediation
Update Imcat to the latest version or apply the necessary patches to fix the Phpinfo Configuration vulnerability.
WeaknessesCWE-200
Authorsritikchaddha
Template tagscve2018cveimcatphpinfoconfigtxjiavuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:txjia:imcat:4.4:*:*:*:*:*:*:*
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-20608