CVE-2009-4025: OS Command Injection
Argument injection vulnerability in the traceroute function in Traceroute.php in the NetTraceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4025?
CVE-2009-4025 has a moderate severity rating due to its potential for remote command execution.
How do I fix CVE-2009-4025?
To fix CVE-2009-4025, upgrade the Net_Traceroute package to version 0.21.2 or later.
What software is affected by CVE-2009-4025?
CVE-2009-4025 affects Net_Traceroute versions prior to 0.21.2, including versions up to 0.21.1.
Can CVE-2009-4025 be exploited remotely?
Yes, CVE-2009-4025 can be exploited by remote attackers through the host parameter.
What is the main vulnerability of CVE-2009-4025?
The main vulnerability of CVE-2009-4025 is argument injection that allows arbitrary shell command execution.