CVE-2015-8476

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
debiandebian_linux
6.0
debiandebian_linux
7.0
debiandebian_linux
8.0
phpmailer_projectphpmailer
𝑥
≤ 5.2.13
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libphp-phpmailer
bullseye
6.2.0-2
fixed
bookworm
6.6.3-1
fixed
sid
6.9.1-1
fixed
trixie
6.9.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libphp-phpmailer
xenial
not-affected
wily
ignored
vivid
Fixed 5.2.9+dfsg-2+deb8u1build0.15.04.1
released
trusty
Fixed 5.1-1+deb6u11build0.14.04.1
released
precise
Fixed 5.1-1+deb6u11build0.12.04.1
released