CVE-2007-3215
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2007-3215
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1.73-4 |
| debian | bullseye | fixed | 1.73-4 |
| debian | forky | fixed | 1.73-4 |
| debian | sid | fixed | 1.73-4 |
| debian | trixie | fixed | 1.73-4 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | phpmailer/phpmailer | <1.7.4 | 1.7.4 |
References
- https://security-tracker.debian.org/tracker/CVE-2007-3215
- https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-6h78-85v2-mmch
- https://cxsecurity.com/issue/WLB-2007060063
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34818
- https://github.com/PHPMailer/PHPMailer
- https://seclists.org/fulldisclosure/2011/Oct/223
- https://sourceforge.net/p/phpmailer/bugs/192
- https://web.archive.org/web/20070714054359/http://larholm.com/2007/06/11/phpmailer-0day-remote-execution
- https://yehg.net/lab/pr0js/advisories/%5BvTiger_5.2.1%5D_rce
Verify integrity in audit chain (admin only). AS-IS.