Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHPMailer‘class.phpmailer.php’CRLF注入漏洞
Vulnerability Description
PHPMailer是一个用于发送电子邮件的PHP类库。 PHPMailer 5.2.14之前版本中存在CRLF注入漏洞,该漏洞源于class.phpmailer.php脚本中的validateAddress函数没有充分过滤邮件地址;class.smtp.php脚本中的sendCommand函数没有充分过滤SMTP命令。攻击者可借助CRLF序列利用该漏洞注入任意SMTP命令。
CVSS Information
N/A
Vulnerability Type
N/A