Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Webwiz vulnerable

  Maran Blog XSS vulnerability

  Sporum Forum XSS vuln.

  PHP Live! Support XSS vuln.

From:Thor Larholm <seclists_(at)_larholm.com>
Date:12.06.2007
Subject:PHPMailer command execution

PHPMailer is a widely deployed utility class used in PHP application to
handle emails sent through sendmail, PHP mailto() or SMTP. It is used in
PHP applications such as WordPress, Mantis, WebCalendar, Group-Office
and Joomla. The last official release happened on July 11, 2005.

If you have configured PHPMailer to use sendmail it has a remote command
execution vulnerability due to a lack of input validation. sendmail is
queried through the popen function which is called with a string
constructed from non-escaped user input.

http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/


Cheers
Thor Larholm

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server