Get the App
SLTechnology News&Howtos  ›  Network Security  › 

How to reproduce remote command execution vulnerabilities in PHPMailer

Shulou Source: shulou.com Published: 2022-06-01 01:27:02 10月04日 Update

It is believed that many inexperienced people have no idea about how to reproduce the remote command execution vulnerability in PHPMailer. Therefore, this paper summarizes the causes and solutions of the problem. Through this article, I hope you can solve this problem.

I. brief introduction of loopholes

PHPMailer is a PHP email creation and transfer class for multiple open source projects: WordPress, Drupal, 1CRM, SugarCRM, Yii, Joomla! Wait.

A security vulnerability exists in PHPMailer < 5.2.18 that allows remote unauthenticated attackers to execute arbitrary code in the context of the Web server user to remotely control the target web application.

Second, the affected version:

PHPMailer

Tags: Vulnerabilities Trojans scripts input commands one sentence content method more version environment problem security helpless for this up and down context code reason background Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno OPPO Reno NVidia Huawei Microsoft Shulou Technology