在 aircheng-org 的 iWebShop-5(版本高达 5.15)中发现了一个安全漏洞。该问题影响 文件中 函数的处理逻辑,导致授权机制缺失(missing authorization)。攻击者可远程利用此漏洞。相关利用代码(exploit)已公开,可能被实际利用。项目方已较早通过 issue 报告获知该问题,但截至目前尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| aircheng-org | iWebShop-5 | 5.0 |
affected |
5.1 |
affected | ||
5.2 |
affected | ||
5.3 |
affected | ||
5.4 |
affected | ||
5.5 |
affected | ||
5.6 |
affected | ||
5.7 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aircheng-org | iWebShop-5 | 5.0 |
cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86666 | 7.3 HIGH | aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload |
| CVE-2026-86669 | 7.3 HIGH | aircheng-org iWebShop-5 systemseller.php login improper authentication |
| CVE-2026-86667 | 4.7 MEDIUM | aircheng-org iWebShop-5 member.php member_list sql injection |
| CVE-2026-86668 | 4.3 MEDIUM | aircheng-org iWebShop-5 pic.php uploadFile cross site scripting |
| CVE-2026-86670 | 3.7 LOW | aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash |
No comments yet