CVE-2007-3215
EPSS 4.4%libphp-phpmailer
發布日:2024/2/2修改日:2026/5/27
描述
PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
受影響套件(4)
- Debian/libphp-phpmailerfrom 0, < 1.73-4
- Debian/libphp-phpmailerfrom 0, < 1.73-2etch1
- Debian/wordpressfrom 0, < 2.2.1-1
- Packagist/phpmailer/phpmailerfrom 0, < 1.7.4
參考連結(9)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2007-3215
- PATCHhttps://github.com/PHPMailer/PHPMailer
- WEBhttps://cxsecurity.com/issue/WLB-2007060063
- WEBhttps://exchange.xforce.ibmcloud.com/vulnerabilities/34818
- WEBhttps://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-6h78-85v2-mmch
- WEBhttps://seclists.org/fulldisclosure/2011/Oct/223
- WEBhttps://sourceforge.net/p/phpmailer/bugs/192
- WEBhttps://web.archive.org/web/20070714054359/http://larholm.com/2007/06/11/phpmailer-0day-remote-execution
- WEBhttps://yehg.net/lab/pr0js/advisories/%5BvTiger_5.2.1%5D_rce