ICEcoder 8.1 及更早版本在 中将通过未转义的文件系统路径传入 shell 命令,使得经过身份验证的用户能够通过目录名称注入操作系统命令。攻击者可以创建包含 shell 元字符的目录名称,并通过访问“Properties(属性)”功能,以 web 服务器用户的身份通过 执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64836 | 8.8 HIGH | ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement |
| CVE-2026-64838 | 8.3 HIGH | ICEcoder through 8.1 Path Traversal via oldFileName Parameter |
No comments yet