Alpine Linux: CVE-2016-10033: phpmailer Remote Code Execution
|8||(AV:N/AC:L/Au:N/C:P/I:P/A:P)||December 29, 2016||August 29, 2017||November 02, 2017|
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Free Nexpose Download
Discover, prioritize, and remediate security risks today!