First published: Thu Jun 14 2007(Updated: )
PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/phpmailer/phpmailer | <1.7.4 | 1.7.4 |
PHPMailer | =1.7 | |
PHPMailer | =1.7.1 | |
PHPMailer | =1.7.2 | |
PHPMailer | =1.7.3 | |
PHPMailer | =1.73 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3215 has a high severity due to its potential to allow remote attackers to execute arbitrary shell commands.
To fix CVE-2007-3215, upgrade PHPMailer to version 1.7.4 or later.
CVE-2007-3215 affects PHPMailer versions prior to 1.7.4, specifically 1.7, 1.7.1, 1.7.2, 1.7.3, and 1.73.
CVE-2007-3215 is a remote command execution vulnerability when PHPMailer is configured to use sendmail.
Yes, CVE-2007-3215 can be exploited remotely if the vulnerable PHPMailer versions are improperly configured.