VulnerabilityModified
CVE-2007-3215
PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
MEDIUM 6.8EPSS 2.41%
Does this matter?
Lower severity and a low EPSS score (2.41%). Track it; it rarely justifies an emergency change on its own.
Description
PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- phpmailer/phpmailer
- Source
- cve@mitre.org
References
- http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/
- http://osvdb.org/37206
- http://osvdb.org/76139
- http://seclists.org/fulldisclosure/2011/Oct/223
- http://secunia.com/advisories/25626Vendor Advisory
- http://secunia.com/advisories/25755
- http://secunia.com/advisories/25758
- http://securityreason.com/securityalert/2802
- http://sourceforge.net/project/shownotes.php?release_id=517428&group_id=157374
- http://www.debian.org/security/2007/dsa-1315
- http://www.securityfocus.com/archive/1/471065/100/0/threaded
- http://www.securityfocus.com/bid/24417
- http://www.vupen.com/english/advisories/2007/2161
- http://www.vupen.com/english/advisories/2007/2267
- http://yehg.net/lab/pr0js/advisories/%5BvTiger_5.2.1%5D_rce
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34818
- https://sourceforge.net/tracker/index.php?func=detail&aid=1734811&group_id=26031&atid=385707
- http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/
- http://osvdb.org/37206
- http://osvdb.org/76139
- http://seclists.org/fulldisclosure/2011/Oct/223
- http://secunia.com/advisories/25626Vendor Advisory
- http://secunia.com/advisories/25755
- http://secunia.com/advisories/25758
- http://securityreason.com/securityalert/2802
- http://sourceforge.net/project/shownotes.php?release_id=517428&group_id=157374
- http://www.debian.org/security/2007/dsa-1315
- http://www.securityfocus.com/archive/1/471065/100/0/threaded
- http://www.securityfocus.com/bid/24417
- http://www.vupen.com/english/advisories/2007/2161
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.