Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-10034

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.679
EPSS Ranking 98.5%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2016-10034


Contact Us

Shodan ® - All rights reserved