oss-sec mailing list archives
Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033]
From: Michael Hess <mlhess () umich edu>
Date: Tue, 27 Dec 2016 09:19:28 -0500
David, You might want to hold off on releasing this until wordpress has a patch out. https://core.trac.wordpress.org/ticket/37210 Michael On Tue, Dec 27, 2016 at 6:45 AM, Dawid Golunski <dawid () legalhackers com> wrote:
PHPMailer < 5.2.18 Remote Code Execution CVE-2016-10033 Attaching an updated version of the advisory with more details + simple PoC. Still incomplete. There will be more updates/exploits soon at: https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html https://twitter.com/dawid_golunski -- Regards, Dawid Golunski https://legalhackers.com t: @dawid_golunski
Current thread:
- PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Dawid Golunski (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Michael Hess (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Solar Designer (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Dawid Golunski (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Dawid Golunski (Dec 27)
- Re: PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033] Dawid Golunski (Dec 27)