Vulnerabilities
Vulnerable Software
Ipcop:  >> Ipcop  >> 1.4.1  Security Vulnerabilities
IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-12-31
Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.
CVSS Score
1.2
EPSS Score
0.001
Published
2005-12-31
Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.
CVSS Score
6.8
EPSS Score
0.026
Published
2005-01-10


Contact Us

Shodan ® - All rights reserved