F5 Networks: K74977440 (CVE-2016-10033): PHPMailer vulnerability CVE-2016-10033
|8||(AV:N/AC:L/Au:N/C:P/I:P/A:P)||December 29, 2016||February 15, 2017||January 31, 2018|
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Free Nexpose Download
Discover, prioritize, and remediate security risks today!