Day: December 29, 2016

SSD Advisory – SwiftMailer Remote Code Execution

Vulnerability Summary The following report describes a remote code execution vulnerability found in SwiftMailer. The vulnerability allows an attacker injecting sendmail program due to insufficient address sanitization. Swift Mailer integrates into any web app written in PHP 5, offering a flexible object-oriented approach to sending emails with a multitude of features Credit An independent security …

SSD Advisory – SwiftMailer Remote Code Execution Read More »

SSD Advisory – ZendMail Remote Command Execution Vulnerability

Vulnerability Summary The following report describes a remote code execution vulnerability found in ZendMail. The vulnerability allows an attacker injecting additional parameters to the sendmail binary via the From address. Credit An independent security researcher Dawid Golunski (https://legalhackers.com/) has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program

?

Get in touch