CVE-2017-15806
HIGHZeta Components Mail < 1.8.2 - Remote Code Execution via Crafted Email Address in Return Path
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-15806. PoCs published by MalwareBenchmark.
AI-analyzed exploit summary The exploit leverages improper sanitization of the return path in the ezcMailMtaTransport class, allowing command injection via the sendmail -X flag to write arbitrary files to the webroot. This results in remote code execution if the attacker can access the written file.
Description
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."
Exploits (1)
The exploit leverages improper sanitization of the return path in the ezcMailMtaTransport class, allowing command injection via the sendmail -X flag to write arbitrary files to the webroot. This results in remote code execution if the attacker can access the written file.
References (6)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H