vendor:
Mail
by:
Kay
8.1
CVSS
HIGH
Arbitrary Command Execution
78
CWE
Product Name: Mail
Affected Version From: <= 1.8.1
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2017-15806
CPE: a:zeta_components:mail:1.8.1
Platforms Tested:
2017
Zeta Components Mail Package Arbitrary Command Execution
It is possible to execute arbitrary shell commands on the remote server by exploiting a vulnerability in the Mail package for Zeta Components. The vulnerability exists in the send method of the ezcMailMtaTransport class. By injecting a payload in the mail body and assigning a specific email address, an attacker can pass extra parameters to the sendmail function, allowing the execution of arbitrary commands.
Mitigation:
Update to a version of Zeta Components Mail package that is higher than 1.8.1. Alternatively, ensure that the 'sendmail' binary does not allow the -X flag to be set.