PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
| Software | From | Fixed in |
|---|---|---|
phpmailer / phpmailer
|
- | 1.7.4 |
phpmailer / phpmailer
|
1.7 | 1.7.x |
phpmailer / phpmailer
|
1.73 | 1.73.x |
phpmailer / phpmailer
|
1.7.2 | 1.7.2.x |
phpmailer / phpmailer
|
1.7.1 | 1.7.1.x |
phpmailer / phpmailer
|
1.7.3 | 1.7.3.x |