CVE-2017-15806

HIGH

Zetacomponents Mail < 1.8.2 - Code Injection

Title source: rule

Description

The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."

Exploits (1)

exploitdb WORKING POC VERIFIED
by MalwareBenchmark · textwebappsphp
https://www.exploit-db.com/exploits/43155

Scores

CVSS v3 8.1
EPSS 0.1646
EPSS Percentile 94.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
zetacomponents/mail < 1.8.2
zetacomponents/mail 0 - 1.8.2Packagist
Published Nov 15, 2017
Tracked Since Feb 18, 2026