Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4677
HistoryJul 26, 2017 - 1:24 a.m.

Remote Code Execution (RCE)

2017-07-2601:24:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

EPSS

0.971

Percentile

99.8%

PHPMailer is vulnerable to remote code execution (RCE) attacks. A malicious user can inject and execute arbitrary code by passing extra parameters to the mail command. This is due to the improper interaction with the library’s escapeshellarg function and internal escaping function performed in PHP. This is a fix for CVE-2016-10033 which was fixed incorrectly.

References