Lucene search

K
f5F5F5:K73926196
HistoryFeb 13, 2017 - 12:00 a.m.

K73926196 : PHPMailer vulnerability CVE-2016-10045

2017-02-1300:00:00
my.f5.com
78

AI Score

10

Confidence

High

EPSS

0.971

Percentile

99.8%

Security Advisory Description

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033. (CVE-2016-10045)
Impact
The Configuration utility component of affected products allows a Manager role user to set the sender field, which can exploit the PHPMailer component. As a result, the remote arbitrary code execution in the context of the web server user is affected and may remotely compromise the target web application.