Pinger 1.0 - Remote Code Execution
CVE-2020-37123
Verified
Description
Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit the unsanitized input in ping.php to write arbitrary PHP files and execute system commands by appending shell metacharacters.
Severity
Critical
CVSS Score
9.8
Exploit Probability
3%
Affected Product
pinger
Published Date
February 7, 2026
Template Author
bswearingen
CVE-2020-37123.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2020-37123
CWE ID:
cwe-78
Remediation Steps
Remove Pinger or apply input validation to sanitize the ping and socket parameters.