Логотип exploitDog
bind:CVE-2017-15806
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-15806

Количество 2

Количество 2

nvd логотип

CVE-2017-15806

около 8 лет назад

The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-hgr8-g756-vmg9

больше 3 лет назад

Zeta Components Mail Arbitrary code execution via a crafted email address

CVSS3: 8.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-15806

The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."

CVSS3: 8.1
20%
Средний
около 8 лет назад
github логотип
GHSA-hgr8-g756-vmg9

Zeta Components Mail Arbitrary code execution via a crafted email address

CVSS3: 8.1
20%
Средний
больше 3 лет назад

Уязвимостей на страницу