The send function in the ezcMailMtaTransport class in Zeta Components...
Vulnerability Description
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-15806
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.exploit-db.com/exploits/43155/
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/
- https://github.com/zetacomponents/Mail/issues/58
- https://github.com/zetacomponents/Mail/releases/tag/1.8.2
- http://www.securityfocus.com/bid/101866
Affected Vendor
zetacomponents
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.