Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2016-10034Command Injection in Zend-mail

CWE-77Command Injection13 documents7 sources
Severity
9.8CRITICALNVD
EPSS
82.3%
top 0.77%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 30
Latest updateMay 14

Description

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Packagistzendframework/zend-mail2.72.7.2+3
NVDzend/zend-mail2.4.10+8

🔴Vulnerability Details

3
OSV
zend-mail remote code execution via Sendmail adapter2022-05-14
GHSA
zend-mail remote code execution via Sendmail adapter2022-05-14
CVEList
CVE-2016-10034: The setFrom function in the Sendmail adapter in the zend-mail component before 22016-12-30

💥Exploits & PoCs

3
Exploit-DB
PHPMailer < 5.2.20 with Exim MTA - Remote Code Execution2017-06-21
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution2017-01-02
Exploit-DB
Zend Framework / zend-mail < 2.4.11 - Remote Code Execution2016-12-30

💬Community

6
HackerOne
Directory Disclose,Email Disclose Zendmail vulnerability2017-06-21
Bugzilla
CVE-2016-10034 php-zendframework-zend-mail: php-zendframework: Parameter injection in setFrom() function [fedora-all]2017-01-02
Bugzilla
CVE-2016-10034 php-ZendFramework: Parameter injection in setFrom() function [fedora-all]2017-01-02
Bugzilla
CVE-2016-10034 php-ZendFramework: Parameter injection in setFrom() function [epel-all]2017-01-02
Bugzilla
CVE-2016-10034 php-ZendFramework2: php-zendframework: Parameter injection in setFrom() function [epel-all]2017-01-02
CVE-2016-10034 — Command Injection in Zend-mail | cvebase