CVE-2009-4025

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
29/11/2009
Last modified:
09/04/2025

Description

Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pear:pear:*:*:*:*:*:*:*:* 0.21.1 (including)
cpe:2.3:a:pear:pear:0.11:*:*:*:*:*:*:*
cpe:2.3:a:pear:pear:0.20:*:*:*:*:*:*:*
cpe:2.3:a:pear:pear:0.21:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools