Pinger 1.0 - Remote Code Execution
Vulnerability Description
Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit the unsanitized input in ping.php to write arbitrary PHP files and execute system commands by appending shell metacharacters.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37123
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Milad Karimi
Affected Vendor
wcchandler
View all reports →