Vulnerabilities > Pear > Pear
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-11-29 | CVE-2009-4025 | OS Command Injection vulnerability in Pear 0.11/0.20/0.21 Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. | 10.0 |
2009-11-29 | CVE-2009-4024 | Code Injection vulnerability in Pear Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. | 10.0 |
2009-11-29 | CVE-2009-4023 | Code Injection vulnerability in Pear 1.1.14 Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111. | 7.5 |