CVE-2017-15806
Last modified
CVE-2017-15806 is a vulnerability of currently unknown severity. The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php.". EPSS estimates a 10.65% chance of exploitation in the next 30 days.
Description
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zetacomponents | < 1.8.2 |
References
- http://www.securityfocus.com/bid/101866Third Party Advisory, VDB Entry
- https://github.com/zetacomponents/Mail/issues/58Issue Tracking, Third Party Advisory
- https://github.com/zetacomponents/Mail/releases/tag/1.8.2Issue Tracking, Release Notes, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/Issue Tracking, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/43155/Issue Tracking, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101866Third Party Advisory, VDB Entry
- https://github.com/zetacomponents/Mail/issues/58Issue Tracking, Third Party Advisory
- https://github.com/zetacomponents/Mail/releases/tag/1.8.2Issue Tracking, Release Notes, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/Issue Tracking, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/43155/Issue Tracking, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-15806?
How severe is CVE-2017-15806?
How do I fix CVE-2017-15806?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-15800Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-15801XnView Classic for Windows Version 2.43 allows attackers to …
- CVE-2017-15802XnView Classic for Windows Version 2.43 allows attackers to …
- CVE-2017-15803XnView Classic for Windows Version 2.43 allows attackers to …
- CVE-2017-15804The glob function in glob.c in the GNU C Library (aka glibc …
- CVE-2017-15805Cisco Small Business SA520 and SA540 devices with firmware 2…
- CVE-2017-15808In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config…
- CVE-2017-15809In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.ph…
- CVE-2017-15810The PopCash.Net Code Integration Tool plugin before 1.1 for …
- CVE-2017-15811The Pootle Button plugin before 1.2.0 for WordPress has XSS …
- CVE-2017-15812The Easy Appointments plugin before 1.12.0 for WordPress has…
- CVE-2017-15813In Android for MSM, Firefox OS for MSM, QRD Android, with al…
Are you affected by CVE-2017-15806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
