CVE-2017-15806

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
15/11/2017
Last modified:
20/04/2025

Description

The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zetacomponents:mail:*:*:*:*:*:*:*:* 1.8.2 (excluding)