VYPR
Vendor

Nicecoder

Products
4
CVEs
18
Across products
27
Status
Private

Products

4

Recent CVEs

18
  • CVE-2026-63722CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP…

  • CVE-2026-64837HigSep 10, 2026
    risk 0.50cvss 8.8epss 0.01

    ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties…

  • CVE-2026-64836HigSep 10, 2026
    risk 0.50cvss 8.8epss 0.00

    ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated…

  • CVE-2022-34026HigSep 22, 2022
    risk 0.49cvss 7.5epss 0.02

    ICEcoder v8.1 allows attackers to execute a directory traversal.

  • CVE-2026-64838HigSep 10, 2026
    risk 0.47cvss 8.3epss 0.00

    ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable…

  • CVE-2024-41373MedJul 26, 2024
    risk 0.41cvss 6.3epss 0.00

    ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.

  • CVE-2024-41375MedJul 26, 2024
    risk 0.40cvss 6.1epss 0.00

    ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php

  • CVE-2024-41374MedJul 26, 2024
    risk 0.40cvss 6.1epss 0.00

    ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php

  • CVE-2021-32106MedJun 8, 2021
    risk 0.28cvss 5.4epss 0.01

    In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.

  • CVE-2021-3862MedJan 17, 2022
    risk 0.24cvss 4.8epss 0.01

    icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2006-1767Apr 13, 2006
    risk 0.04cvss —epss 0.08

    Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (5) browse.php, (6)…

  • CVE-2009-4624Jan 18, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005-3843.

  • CVE-2006-7017Feb 15, 2007
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the admin_template_path parameter to admin/ scripts (1) app_change_email.php, (2) app_change_pwd.php, (3) app_mod_rewrite.php, (4)…

  • CVE-2007-0364Jan 19, 2007
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name,…

  • CVE-2006-0688Feb 15, 2006
    risk 0.03cvss —epss 0.04

    PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

  • CVE-2007-0349Jan 19, 2007
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.

  • CVE-2005-3843Nov 26, 2005
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in faq.php in Nicecoder iDesk 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

  • CVE-2001-0451Jun 27, 2001
    risk 0.00cvss —epss 0.02

    INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.