CVE-2016-10033
30.12.2016, 19:59
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
| Vendor | Product | Version |
|---|---|---|
| phpmailer_project | phpmailer | 𝑥 < 5.2.18 |
| wordpress | wordpress | 𝑥 ≤ 4.7 |
| joomla | joomla\! | 1.5.0 ≤ 𝑥 ≤ 3.6.5 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libphp-phpmailer |
|
References