5
CVSSv2

CVE-2015-8476

Published: 16/12/2015 Updated: 06/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple CRLF injection vulnerabilities in PHPMailer prior to 5.2.14 allow malicious users to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 6.0

debian debian linux 7.0

debian debian linux 8.0

phpmailer project phpmailer

Vendor Advisories

Debian Bug report logs - #807265 libphp-phpmailer: CVE-2015-8476: Message Injection Vulnerability Package: libphp-phpmailer; Maintainer for libphp-phpmailer is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for libphp-phpmailer is src:libphp-phpmailer (PTS, buildd, popcon) Reported by: Salvatore B ...
Takeshi Terada discovered a vulnerability in PHPMailer, a PHP library for email transfer, used by many CMSs The library accepted email addresses and SMTP commands containing line breaks, which can be abused by an attacker to inject messages For the oldstable distribution (wheezy), this problem has been fixed in version 51-11 For the stable dis ...