Description
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter problem.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1949-1 | New php-net-ping packages fix arbitrary code execution |
EUVD |
EUVD-2009-3995 | Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter problem. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T06:45:50.941Z
Reserved: 2009-11-20T00:00:00.000Z
Link: CVE-2009-4024
No data.
Status : Modified
Published: 2009-11-29T13:07:35.733
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-4024
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD