oss-sec mailing list archives
PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033]
From: Dawid Golunski <dawid () legalhackers com>
Date: Tue, 27 Dec 2016 09:45:48 -0200
PHPMailer < 5.2.18 Remote Code Execution CVE-2016-10033 Attaching an updated version of the advisory with more details + simple PoC. Still incomplete. There will be more updates/exploits soon at: https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html https://twitter.com/dawid_golunski -- Regards, Dawid Golunski https://legalhackers.com t: @dawid_golunski
Attachment:
PHPMailer-Exploit.txt
Description:
Current thread:
- PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Dawid Golunski (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Michael Hess (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Solar Designer (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Dawid Golunski (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Dawid Golunski (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Dawid Golunski (Dec 27)