Vulnerability Name: | CVE-2015-8476 (CCN-108544) | ||||||||||||||||||||||||
Assigned: | 2015-12-04 | ||||||||||||||||||||||||
Published: | 2015-12-04 | ||||||||||||||||||||||||
Updated: | 2016-12-06 | ||||||||||||||||||||||||
Summary: | Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) 4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8476 Source: FEDORA Type: UNKNOWN FEDORA-2015-abf9659276 Source: FEDORA Type: UNKNOWN FEDORA-2015-39522bb8c9 Source: CCN Type: PHPMailer Web site Worx International Inc Source: CCN Type: oss-sec Mailing List, Fri, 4 Dec 2015 20:04:30 +0100 CVE Request: PHPMailer Message Injection Vulnerability Source: CCN Type: oss-sec Mailing List, Fri, 4 Dec 2015 23:34:29 -0500 (EST) Re: CVE Request: PHPMailer Message Injection Vulnerability Source: DEBIAN Type: UNKNOWN DSA-3416 Source: MLIST Type: UNKNOWN [oss-security] 20151204 CVE Request: PHPMailer Message Injection Vulnerability Source: MLIST Type: UNKNOWN [oss-security] 20151204 Re: CVE Request: PHPMailer Message Injection Vulnerability Source: BID Type: UNKNOWN 78619 Source: CCN Type: BID-78619 PHPMailer 'class.phpmailer.php' Security Bypass Vulnerability Source: XF Type: UNKNOWN phpmailer-cve20158476-message-injection(108544) Source: CCN Type: PHPMailer - GitHub Web site PHPMailer Source: CONFIRM Type: UNKNOWN https://github.com/PHPMailer/PHPMailer/commit/6687a96a18b8f12148881e4ddde795ae477284b0 Source: CONFIRM Type: Vendor Advisory https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.14 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8476 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |