10
CVSSv2

CVE-2009-4024

Published: 29/11/2009 Updated: 17/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package prior to 2.4.5 for PEAR allows remote malicious users to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter problem.

Vulnerable Product Search on Vulmon Subscribe to Product

pear pear 2.1

pear pear 1.0.1

pear pear

pear pear 2.4.3

pear pear 2.4.2

pear pear 1.0

pear pear 0.1

pear pear 2.4.1

pear pear 2.4

pear pear 2.3

pear pear 2.2

Vendor Advisories

It was discovered that php-net-ping, a PHP PEAR module to execute ping independently of the Operating System, performs insufficient input sanitising, which might be used to inject arguments (no CVE yet) or execute arbitrary commands (CVE-2009-4024) on a system that uses php-net-ping For the oldstable distribution (etch), this problem has been fixe ...