CVE-2016-10033
30.12.2016, 19:59
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Vendor | Product | Version |
---|---|---|
phpmailer_project | phpmailer | 𝑥 < 5.2.18 |
wordpress | wordpress | 𝑥 ≤ 4.7 |
joomla | joomla\! | 1.5.0 ≤ 𝑥 ≤ 3.6.5 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libphp-phpmailer |
|
References