Vulnerabilities > Ipcop

DATE CVE VULNERABILITY TITLE RISK
2015-01-02 CVE-2013-7418 Command Injection vulnerability in Ipcop 2.1.2/2.1.4
cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell metacharacters in the TABLE parameter.
network
low complexity
ipcop CWE-77
6.5
2015-01-02 CVE-2013-7417 Cross-site Scripting vulnerability in Ipcop 2.1.2
Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.
network
ipcop CWE-79
4.3
2005-12-31 CVE-2005-4660 Unspecified vulnerability in Ipcop
Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.
local
high complexity
ipcop
1.2
2005-12-31 CVE-2005-4659 Information Disclosure vulnerability in IPCop Backup Key
IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.
local
low complexity
ipcop
2.1
2005-01-10 CVE-2004-1210 HTML Injection vulnerability in Ipcop 1.4.1
Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.
network
ipcop
6.8