Icecoder

Icecoder

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 10.09.2026 13:51:07
  • Zuletzt bearbeitet 10.09.2026 19:58:20

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFile...

  • EPSS 0.54%
  • Veröffentlicht 10.09.2026 13:51:06
  • Zuletzt bearbeitet 10.09.2026 19:58:20

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names...

  • EPSS 0.45%
  • Veröffentlicht 10.09.2026 13:51:05
  • Zuletzt bearbeitet 10.09.2026 19:58:20

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succ...

  • EPSS 0.99%
  • Veröffentlicht 19.08.2026 19:13:45
  • Zuletzt bearbeitet 24.09.2026 20:06:30

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attac...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 26.07.2024 17:15:12
  • Zuletzt bearbeitet 22.04.2025 13:59:24

ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 26.07.2024 17:15:12
  • Zuletzt bearbeitet 22.04.2025 13:59:40

ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php

Exploit
  • EPSS 0.34%
  • Veröffentlicht 26.07.2024 17:15:12
  • Zuletzt bearbeitet 22.04.2025 13:59:54

ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php

Exploit
  • EPSS 1.48%
  • Veröffentlicht 22.09.2022 18:15:09
  • Zuletzt bearbeitet 09.07.2026 01:17:32

ICEcoder v8.1 allows attackers to execute a directory traversal.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 17.01.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:22:40

icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit
  • EPSS 0.86%
  • Veröffentlicht 08.06.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:06:51

In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.