PHPPing 0.1 - Remote Command Execution



EKU-ID: 27819 CVE: OSVDB-ID:
Author: gregory Le Bras Published: 2003-03-06 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/7030/info

A vulnerability has been reported in PHPPing that may allow remote attackers to execute commands on vulnerable systems.

The vulnerability exists in the index.php script file. Some variables are not properly sanitized of malicious shell metacharacters. An attacker can exploit this vulnerability by executing the PHPPing script and include malicious shell metacharacters as values for various parameters.

http://www.target.com/phpping/index.php?pingto=www.test.com%20|%20dir