CVE-2007-3215

EPSS 4.4%

PHPMailer Shell command injection

Published: 2/2/2024Modified: 5/27/2026
Also known as:GHSA-6h78-85v2-mmchDEBIAN-CVE-2007-3215

Description

PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.

Affected packages (4)

References (9)