CVE-2009-4024: Code Injection
Argument injection vulnerability in the ping function in Ping.php in the NetPing package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter problem.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4024?
CVE-2009-4024 is considered to have a high severity due to the potential for remote command execution.
How do I fix CVE-2009-4024?
To fix CVE-2009-4024, upgrade to Net_Ping version 2.4.5 or later.
What types of attacks can be performed using CVE-2009-4024?
CVE-2009-4024 allows attackers to execute arbitrary shell commands through the host parameter.
Which versions of Net_Ping are affected by CVE-2009-4024?
CVE-2009-4024 affects Net_Ping versions prior to 2.4.5, including versions 1.0 through 2.4.4.
What is the impact of CVE-2009-4024 on system security?
The impact of CVE-2009-4024 on system security includes the risk of unauthorized command execution, potentially compromising the system.