Lucene search

K
f5F5F5:K79502122
HistoryJan 16, 2017 - 12:00 a.m.

K79502122 : Zend Framework vulnerability CVE-2016-10034

2017-01-1600:00:00
my.f5.com
42

AI Score

9.6

Confidence

High

EPSS

0.964

Percentile

99.6%

Security Advisory Description

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted e-mail address. (CVE-2016-10034)
Impact
There is no impact; F5 products are not affected by this vulnerability.