在 aircheng-org iWebShop-5(版本 ≤ 5.15)中已发现一个安全漏洞。受影响的是文件 中的 功能。该漏洞可导致无限制文件上传(即未对上传文件的类型、大小或来源进行充分校验),且攻击者可远程利用。相关利用工具/漏洞利用代码已公开发布,可能被用于实际攻击。项目方此前已通过问题报告得知该问题,但尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| aircheng-org | iWebShop-5 | 5.0 |
affected |
5.1 |
affected | ||
5.2 |
affected | ||
5.3 |
affected | ||
5.4 |
affected | ||
5.5 |
affected | ||
5.6 |
affected | ||
5.7 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aircheng-org | iWebShop-5 | 5.0 |
cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86665 | 7.3 HIGH | aircheng-org iWebShop-5 update.php index authorization |
| CVE-2026-86669 | 7.3 HIGH | aircheng-org iWebShop-5 systemseller.php login improper authentication |
| CVE-2026-86667 | 4.7 MEDIUM | aircheng-org iWebShop-5 member.php member_list sql injection |
| CVE-2026-86668 | 4.3 MEDIUM | aircheng-org iWebShop-5 pic.php uploadFile cross site scripting |
| CVE-2026-86670 | 3.7 LOW | aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash |
No comments yet