CVE-2016-10033
Description
PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
CISA KEV
- Vendor
- PHP
- Product
- PHPMailer
- Due date
- 2025-07-28
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.18 ; https://github.com/advisories/GHSA-5f37-gxvh-23v6 ; https://nvd.nist.gov/vuln/detail/CVE-2016-10033
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-10033
Vendor advisory: arch — https://security.archlinux.org/ASA-201701-22
Exploits
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 4.7.1-1 | |
| debian | bookworm | fixed | 5.2.14+dfsg-2.1 |
| debian | bullseye | fixed | 5.2.14+dfsg-2.1 |
| debian | forky | fixed | 5.2.14+dfsg-2.1 |
| debian | sid | fixed | 5.2.14+dfsg-2.1 |
| debian | trixie | fixed | 5.2.14+dfsg-2.1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | phpmailer/phpmailer | >=5.0.0,<5.2.18 | 5.2.18 |
References
- https://security.archlinux.org/ASA-201701-22
- https://security-tracker.debian.org/tracker/CVE-2016-10033
- https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-5f37-gxvh-23v6
- https://nvd.nist.gov/vuln/detail/CVE-2016-10033
- https://www.exploit-db.com/exploits/42221
- https://www.exploit-db.com/exploits/42024
- https://www.exploit-db.com/exploits/41996
- https://www.exploit-db.com/exploits/41962
- https://www.exploit-db.com/exploits/40986
- https://www.exploit-db.com/exploits/40974
- https://www.exploit-db.com/exploits/40970
- https://www.exploit-db.com/exploits/40969
- https://www.exploit-db.com/exploits/40968
- https://www.drupal.org/psa-2016-004
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-10033
- https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html
- https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities
- https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.18
- https://github.com/PHPMailer/PHPMailer
- https://github.com/FriendsOfPHP/security-advisories/blob/master/phpmailer/phpmailer/CVE-2016-10033.yaml
- https://developer.joomla.org/security-centre/668-20161205-phpmailer-security-advisory.html
- http://packetstormsecurity.com/files/140291/PHPMailer-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/140350/PHPMailer-Sendmail-Argument-Injection.html
- http://seclists.org/fulldisclosure/2016/Dec/78
- http://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection
Verify integrity in audit chain (admin only). AS-IS.