Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vggq-52m7-59x7

Опубликовано: 15 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, directly into system-level operations without proper input sanitation. By modifying the email password field to include shell metacharacters and issuing a save-and-test-mail action, an authenticated attacker can execute arbitrary operating system commands with the privileges of the web interface, resulting in full system compromise.

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, directly into system-level operations without proper input sanitation. By modifying the email password field to include shell metacharacters and issuing a save-and-test-mail action, an authenticated attacker can execute arbitrary operating system commands with the privileges of the web interface, resulting in full system compromise.

EPSS

Процентиль: 61%
0.00418
Низкий

8.7 High

CVSS4

Дефекты

CWE-78

Связанные уязвимости

nvd
3 месяца назад

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, directly into system-level operations without proper input sanitation. By modifying the email password field to include shell metacharacters and issuing a save-and-test-mail action, an authenticated attacker can execute arbitrary operating system commands with the privileges of the web interface, resulting in full system compromise.

EPSS

Процентиль: 61%
0.00418
Низкий

8.7 High

CVSS4

Дефекты

CWE-78