VDB
CVE-2009-4025
CVE-2009-4025
PUBLISHED
CVSS 10 CRITICAL
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party information.
EPSS 5.80% · 90.7th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
5.80%
90.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| pear | pear | 0, 0.11, 0.20 |
Timeline
- Nov 28, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://pear.php.net/advisory20091114-01.txt url
- FEDORA-2009-11617 vendor-advisory
- GLSA-200911-06 vendor-advisory
- FEDORA-2009-12083 vendor-advisory
- http://pear.php.net/package/Net_Traceroute/download/0.21.2 url
- [oss-security] 20091123 CVE request: Argument injections in multiple PEAR packages mailing-list
- 37497 third-party-advisory
- 37094 vdb
- http://blog.pear.php.net/2009/11/14/net_traceroute-and-net_ping-security-advisory/ url
- ADV-2009-3321 vdb
- 37503 third-party-advisory
- FEDORA-2009-11551 vendor-advisory
- nettraceroute-traceroute-command-execution(54391) vdb
- 60515 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2009-4025 advisory
- http://blog.pear.php.net/2009/11/14/net_traceroute-and-net_ping-security-advisory url