Vulnerabilities (CVE)

Filtered by vendor Zetacomponents Subscribe
Filtered by product Mail
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15806 1 Zetacomponents 1 Mail 2024-02-04 6.8 MEDIUM 8.1 HIGH
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."