{"api_version":"1","generated_at":"2026-07-23T11:57:08+00:00","cve":"CVE-2008-7319","urls":{"html":"https://cve.report/CVE-2008-7319","api":"https://cve.report/api/cve/CVE-2008-7319.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-7319","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-7319"},"summary":{"title":"CVE-2008-7319","description":"The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-11-07 21:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-77","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2017/11/07/4","name":"http://www.openwall.com/lists/oss-security/2017/11/07/4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Mailing List","Patch","Third Party Advisory"],"title":"oss-security - Net::Ping::External command injections","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.debian.org/881097","name":"https://bugs.debian.org/881097","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"#881097 - libnet-ping-external-perl: CVE-2008-7319: command injection via crafted arguments - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://matthias.sdfeu.org/devel/net-ping-external-cmd-injection.patch","name":"http://matthias.sdfeu.org/devel/net-ping-external-cmd-injection.patch","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"https://rt.cpan.org/Public/Bug/Display.html?id=33230","name":"https://rt.cpan.org/Public/Bug/Display.html?id=33230","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Bug #33230 for Net-Ping-External: shell exploit and resolv error","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-7319","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-7319","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"7319","vulnerable":"1","versionEndIncluding":"0.15","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"net-ping-external_project","cpe5":"net-ping-external","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"perl","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:03:36.429Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://rt.cpan.org/Public/Bug/Display.html?id=33230"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugs.debian.org/881097"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2017/11/07/4"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://matthias.sdfeu.org/devel/net-ping-external-cmd-injection.patch"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-07T21:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://rt.cpan.org/Public/Bug/Display.html?id=33230"},{"tags":["x_refsource_MISC"],"url":"https://bugs.debian.org/881097"},{"tags":["x_refsource_MISC"],"url":"http://www.openwall.com/lists/oss-security/2017/11/07/4"},{"tags":["x_refsource_MISC"],"url":"http://matthias.sdfeu.org/devel/net-ping-external-cmd-injection.patch"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-7319","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://rt.cpan.org/Public/Bug/Display.html?id=33230","refsource":"MISC","url":"https://rt.cpan.org/Public/Bug/Display.html?id=33230"},{"name":"https://bugs.debian.org/881097","refsource":"MISC","url":"https://bugs.debian.org/881097"},{"name":"http://www.openwall.com/lists/oss-security/2017/11/07/4","refsource":"MISC","url":"http://www.openwall.com/lists/oss-security/2017/11/07/4"},{"name":"http://matthias.sdfeu.org/devel/net-ping-external-cmd-injection.patch","refsource":"MISC","url":"http://matthias.sdfeu.org/devel/net-ping-external-cmd-injection.patch"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-7319","datePublished":"2017-11-07T21:00:00.000Z","dateReserved":"2017-11-07T00:00:00.000Z","dateUpdated":"2024-09-17T00:51:37.142Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-07 21:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-77","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:net-ping-external_project:net-ping-external:*:*:*:*:*:perl:*:*","versionEndIncluding":"0.15","matchCriteriaId":"A5D3C017-6D62-478C-AFCE-21AD78D07D9D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"7319","Ordinal":"1","Title":"CVE-2008-7319","CVE":"CVE-2008-7319","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"7319","Ordinal":"1","NoteData":"The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.","Type":"Description","Title":"CVE-2008-7319"},{"CveYear":"2008","CveId":"7319","Ordinal":"2","NoteData":"2017-11-07","Type":"Other","Title":"Published"}]}}}