Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2016-10033 PoC — PHPMailer 安全漏洞

Source
Associated Vulnerability
Title: PHPMailer 安全漏洞 (CVE-2016-10033)
Description:The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Readme
# CVE-2016-10033 – PHPMailer Remote Code Execution

## 📌 Description
This repository contains a proof-of-concept (PoC) exploit for **CVE-2016-10033**,  
a vulnerability in **PHPMailer** versions prior to **5.2.18**.  
The issue occurs when the `$additional_parameters` argument of PHP's built-in  
`mail()` function is improperly handled, allowing attackers to inject additional  
command-line parameters into **sendmail**. This can be abused to write arbitrary  
PHP code to a web-accessible directory, leading to **Remote Code Execution (RCE)**.

---

## ⚠️ Disclaimer
This project is for **educational and authorized security testing purposes only**.  
Do not use this exploit against systems you do not own or have permission to test.  
The author takes **no responsibility** for any misuse of this code.

---

## 🛠 Affected Versions
- PHPMailer ≤ **5.2.17**  
- PHP when configured to use `sendmail`  
- `sendmail_path` defined and accessible  

---
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →