ICEcoder 8.1 及更早版本中存在路径遍历漏洞,其成因在于文件控制端点中的文档根目录限制检查存在逻辑错误。 校验函数将 的结果与布尔值 进行比较,该比较永远无法成功。这使得经过身份验证的攻击者可以在文件参数中提交遍历序列或绝对路径,从而能够读取、写入或删除配置文档根目录之外的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64837 | 8.8 HIGH | ICEcoder through 8.1 OS Command Injection via lib/properties.php |
| CVE-2026-64838 | 8.3 HIGH | ICEcoder through 8.1 Path Traversal via oldFileName Parameter |
No comments yet