CVE-2013-7418

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
02/01/2015
Last modified:
05/01/2015

Description

cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell metacharacters in the TABLE parameter. NOTE: this can be exploited remotely by leveraging a separate cross-site scripting (XSS) vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ipcop:ipcop:*:*:*:*:*:*:*:* 2.1.4 (including)