How to reproduce remote command execution vulnerabilities in PHPMailer
It is believed that many inexperienced people have no idea about how to reproduce the remote command execution vulnerability in PHPMailer. Therefore, this paper summarizes the causes and solutions of the problem. Through this article, I hope you can solve this problem.
I. brief introduction of loopholes
PHPMailer is a PHP email creation and transfer class for multiple open source projects: WordPress, Drupal, 1CRM, SugarCRM, Yii, Joomla! Wait.
A security vulnerability exists in PHPMailer < 5.2.18 that allows remote unauthenticated attackers to execute arbitrary code in the context of the Web server user to remotely control the target web application.
Second, the affected version:
PHPMailer