BigantsoftCVEs & Vulnerabilities

17 CVEs affecting Bigantsoft products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

bigant server 10bigant im message server 3bigant messenger 2bigant office messenger 5 2
CVE-2022-23347KEVHIGHin the wild

BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

11 Apr 2026
7.5
CVSS
CVE-2025-0364CRITICAL

BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the attacker can upload and execute arbitrary PHP code using the "Cloud Storage Addin," leading to unauthenticated code execution.

4 Feb 2025
9.8
CVSS
CVE-2024-54761MEDIUMpoc

BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

9 Jan 2025
6.3
CVSS
CVE-2021-43430HIGH

An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.

7 Apr 2022
8.8
CVSS
CVE-2022-26281HIGH

BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

5 Apr 2022
7.5
CVSS
CVE-2022-23352HIGH

An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).

21 Mar 2022
7.5
CVSS
CVE-2022-23350MEDIUM

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.

21 Mar 2022
5.4
CVSS
CVE-2022-23349HIGH

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

21 Mar 2022
8.8
CVSS
CVE-2022-23348MEDIUM

BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

21 Mar 2022
5.3
CVSS
CVE-2022-23346HIGH

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

21 Mar 2022
8.8
CVSS
CVE-2022-23345HIGH

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

21 Mar 2022
7.5
CVSS
CVE-2012-6275CRITICALpoc

Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.

24 Feb 2013
10.0
CVSS
CVE-2012-6274MEDIUMpoc

BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.

24 Feb 2013
5.0
CVSS
CVE-2012-6273HIGH

SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request.

24 Feb 2013
7.5
CVSS
CVE-2009-4661MEDIUMpoc

Multiple buffer overflows in BigAnt Server 2.50 SP6 and earlier allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted ZIP file that is not properly handled when the victim uses the (1) Update or (2) Plug-In console menu item.

3 Mar 2010
4.3
CVSS
CVE-2009-4660CRITICALpoc

Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 6660.

3 Mar 2010
10.0
CVSS
CVE-2008-1914CRITICALpoc

Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in a request to TCP port 6080. NOTE: some of these details are obtained from third party information.

22 Apr 2008
10.0
CVSS
← PrevPage 1 / 1Next →