CVE-2007-3215

N/A Unknown
Published: June 14, 2007 Modified: April 23, 2026
View on NVD

Description

PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/37206
Source: cve@mitre.org
http://osvdb.org/76139
Source: cve@mitre.org
http://secunia.com/advisories/25626
Source: cve@mitre.org
Vendor Advisory
http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/37206
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/76139
Source: af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2011/Oct/223
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25626
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/25755
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25758
Source: af854a3a-2127-422b-91ae-364da2661108
http://securityreason.com/securityalert/2802
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2007/dsa-1315
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/471065/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/24417
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2161
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2267
Source: af854a3a-2127-422b-91ae-364da2661108
http://yehg.net/lab/pr0js/advisories/%5BvTiger_5.2.1%5D_rce
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/34818
Source: af854a3a-2127-422b-91ae-364da2661108

34 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
4.4%
89th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

phpmailer