CVE-2013-7418

IPCop < 2.1.5 - Authenticated Remote Code Execution via iptablesgui.cgi TABLE Parameter

Title source: llm
STIX 2.1

Description

cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell metacharacters in the TABLE parameter. NOTE: this can be exploited remotely by leveraging a separate cross-site scripting (XSS) vulnerability.

Scores

EPSS 0.0240
EPSS Percentile 81.9%

Details

CWE
CWE-77
Status published
Products (1)
ipcop/ipcop < 2.1.4
Published Jan 02, 2015
Tracked Since Feb 18, 2026