CVE-2026-64837: ICEcoder through 8.1 OS Command Injection via lib/properties.php

Published Sep 10, 2026
·
Updated

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as the web-server user via popen().

Affected Software

1 affected component
ICEcoder><=8.1

Event History

Sep 10, 2026
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated ICEcoder user can exploit it. The attacker needs permission to create a directory with shell metacharacters in its name and access the Properties function.

2

What level of access can an attacker obtain?

Injected commands run as the web-server user. This can affect confidentiality, integrity, and availability of resources accessible to that account.

3

Are installations affected by user-created directory names?

Yes. The vulnerable path is passed to a shell command without escaping, so directory names containing shell metacharacters can be used as the injection vector.

4

How can I check for possible exploitation?

Review directory names available to ICEcoder users for shell metacharacters and inspect web-server activity for unexpected commands run through the Properties function. The vulnerable code path is lib/properties.php.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203