Vulnerability Description
IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, directly into system-level operations without proper input sanitation. By modifying the email password field to include shell metacharacters and issuing a save-and-test-mail action, an authenticated attacker can execute arbitrary operating system commands with the privileges of the web interface, resulting in full system compromise.
Related Weaknesses (CWE)
References
- https://sourceforge.net/projects/ipcop/
- https://www.exploit-db.com/exploits/50183
- https://www.ipcop.org/
- https://www.vulncheck.com/advisories/ipcop-authenticated-rce
FAQ
What is CVE-2021-4466?
CVE-2021-4466 is a documented vulnerability. IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-cont...
How severe is CVE-2021-4466?
CVSS scoring is not yet available for CVE-2021-4466. Check NVD for updates.
Is there a patch for CVE-2021-4466?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.