Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2016-10033

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted Sender property.

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
Software From Fixed in
phpmailer_project / phpmailer - 5.2.18
WordPress / wordpress - 4.7.x
Joomla / joomla 1.5.0 3.6.5.x
phpmailer / phpmailer 5.0.0 5.2.18