在 aircheng-org iWebShop-5(版本最高至 5.15)中发现了一个安全弱点。受影响的组件是文件 中的 函数。对参数 的操作会导致 SQL 注入漏洞。该漏洞可被远程利用。目前该漏洞的利用代码(exploit)已公开,可被用于发起攻击。项目维护方此前已通过问题报告获知此问题,但尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| aircheng-org | iWebShop-5 | 5.0 |
affected |
5.1 |
affected | ||
5.2 |
affected | ||
5.3 |
affected | ||
5.4 |
affected | ||
5.5 |
affected | ||
5.6 |
affected | ||
5.7 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aircheng-org | iWebShop-5 | 5.0 |
cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86665 | 7.3 HIGH | aircheng-org iWebShop-5 update.php index authorization |
| CVE-2026-86666 | 7.3 HIGH | aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload |
| CVE-2026-86669 | 7.3 HIGH | aircheng-org iWebShop-5 systemseller.php login improper authentication |
| CVE-2026-86668 | 4.3 MEDIUM | aircheng-org iWebShop-5 pic.php uploadFile cross site scripting |
| CVE-2026-86670 | 3.7 LOW | aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash |
No comments yet