ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2016-10033”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2016-10033
Published
2016-12-30
CVSS:
9.8
ShadowTrackr CVSS:
9.2
Summary:
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.