PT-2015-2870 · Php+1 · Phpmailer+1
Takeshi Terada
·
Publicado
2015-12-13
·
Atualizado
2020-03-05
·
CVE-2015-8476
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHPMailer versions prior to 5.2.14
Description
The issue allows attackers to inject arbitrary SMTP commands via CRLF sequences in an email address to the
validateAddress function in class.phpmailer.php or an SMTP command to the sendCommand function in class.smtp.php. This can be exploited by injecting line breaks into valid email addresses, which are not handled correctly in some contexts.Recommendations
For versions prior to 5.2.14, update to version 5.2.14 or later to resolve the issue.
As a temporary workaround, consider manually stripping line breaks from email addresses before passing them to PHPMailer.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Phpmailer