CVE-2017-15806
HIGHZetacomponents Mail < 1.8.2 - Code Injection
Title source: ruleDescription
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by MalwareBenchmark · textwebappsphp
https://www.exploit-db.com/exploits/43155
References (6)
Scores
CVSS v3
8.1
EPSS
0.1646
EPSS Percentile
94.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (2)
zetacomponents/mail
< 1.8.2
zetacomponents/mail
0 - 1.8.2Packagist
Published
Nov 15, 2017
Tracked Since
Feb 18, 2026