Nicecoder
Products
4- 10 CVEs
- 9 CVEs
- 6 CVEs
- 2 CVEs
Recent CVEs
18| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-63722 | Cri | 0.57 | 9.8 | 0.01 | Aug 19, 2026 | ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP… | ||
| CVE-2026-64837 | Hig | 0.50 | 8.8 | 0.01 | Sep 10, 2026 | ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties… | ||
| CVE-2026-64836 | Hig | 0.50 | 8.8 | 0.00 | Sep 10, 2026 | ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated… | ||
| CVE-2022-34026 | Hig | 0.49 | 7.5 | 0.02 | Sep 22, 2022 | ICEcoder v8.1 allows attackers to execute a directory traversal. | ||
| CVE-2026-64838 | Hig | 0.47 | 8.3 | 0.00 | Sep 10, 2026 | ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable… | ||
| CVE-2024-41373 | Med | 0.41 | 6.3 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php. | ||
| CVE-2024-41375 | Med | 0.40 | 6.1 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php | ||
| CVE-2024-41374 | Med | 0.40 | 6.1 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php | ||
| CVE-2021-32106 | Med | 0.28 | 5.4 | 0.01 | Jun 8, 2021 | In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed. | ||
| CVE-2021-3862 | Med | 0.24 | 4.8 | 0.01 | Jan 17, 2022 | icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2006-1767 | 0.04 | — | 0.08 | Apr 13, 2006 | Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (5) browse.php, (6)… | |||
| CVE-2009-4624 | 0.03 | — | 0.01 | Jan 18, 2010 | SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005-3843. | |||
| CVE-2006-7017 | 0.03 | — | 0.03 | Feb 15, 2007 | Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the admin_template_path parameter to admin/ scripts (1) app_change_email.php, (2) app_change_pwd.php, (3) app_mod_rewrite.php, (4)… | |||
| CVE-2007-0364 | 0.03 | — | 0.03 | Jan 19, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name,… | |||
| CVE-2006-0688 | 0.03 | — | 0.04 | Feb 15, 2006 | PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. | |||
| CVE-2007-0349 | 0.00 | — | 0.02 | Jan 19, 2007 | Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter. | |||
| CVE-2005-3843 | 0.00 | — | 0.01 | Nov 26, 2005 | SQL injection vulnerability in faq.php in Nicecoder iDesk 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |||
| CVE-2001-0451 | 0.00 | — | 0.02 | Jun 27, 2001 | INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1. |
- risk 0.57cvss 9.8epss 0.01
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP…
- risk 0.50cvss 8.8epss 0.01
ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties…
- risk 0.50cvss 8.8epss 0.00
ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated…
- risk 0.49cvss 7.5epss 0.02
ICEcoder v8.1 allows attackers to execute a directory traversal.
- risk 0.47cvss 8.3epss 0.00
ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable…
- risk 0.41cvss 6.3epss 0.00
ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
- risk 0.40cvss 6.1epss 0.00
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
- risk 0.40cvss 6.1epss 0.00
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
- risk 0.28cvss 5.4epss 0.01
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.
- risk 0.24cvss 4.8epss 0.01
icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2006-1767Apr 13, 2006risk 0.04cvss —epss 0.08
Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (5) browse.php, (6)…
- CVE-2009-4624Jan 18, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005-3843.
- CVE-2006-7017Feb 15, 2007risk 0.03cvss —epss 0.03
Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the admin_template_path parameter to admin/ scripts (1) app_change_email.php, (2) app_change_pwd.php, (3) app_mod_rewrite.php, (4)…
- CVE-2007-0364Jan 19, 2007risk 0.03cvss —epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name,…
- CVE-2006-0688Feb 15, 2006risk 0.03cvss —epss 0.04
PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
- CVE-2007-0349Jan 19, 2007risk 0.00cvss —epss 0.02
Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.
- CVE-2005-3843Nov 26, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in faq.php in Nicecoder iDesk 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
- CVE-2001-0451Jun 27, 2001risk 0.00cvss —epss 0.02
INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.