FreeBSD: VID-C7656D4C-CB60-11E6-A9A5-B499BAEBFEAF (CVE-2016-10033): phpmailer -- Remote Code Execution
|8||(AV:N/AC:L/Au:N/C:P/I:P/A:P)||December 25, 2016||December 26, 2016||October 22, 2017|
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Free Nexpose Download
Discover, prioritize, and remediate security risks today!