ICEcoder 8.1 及更早版本在文件移动和重命名操作中未能正确验证 参数,允许经过身份验证的用户将文件从文档根目录之外移动进来。攻击者可以利用 中的路径遍历序列,将 PHP 进程有写权限的文件移动到 Web 可访问的项目目录中,从而泄露文件内容并删除原始文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64836 | 8.8 HIGH | ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement |
| CVE-2026-64837 | 8.8 HIGH | ICEcoder through 8.1 OS Command Injection via lib/properties.php |
No comments yet