CVE-2017-15806
Summary
| CVE | CVE-2017-15806 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-15 16:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php." |
Risk And Classification
Primary CVSS: v3.0 8.1 HIGH from [email protected]
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.164570000 probability, percentile 0.949450000 (date 2026-05-13)
Problem Types: CWE-94 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 8.1 | HIGH | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zetacomponents | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/zetacomponents/Mail/issues/58 | af854a3a-2127-422b-91ae-364da2661108 | github.com | Issue Tracking, Third Party Advisory |
| Site not found · GitHub Pages | af854a3a-2127-422b-91ae-364da2661108 | kay-malwarebenchmark.github.io | Issue Tracking, Third Party Advisory |
| Zeta Components Mail 1.8.1 - Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Issue Tracking, Third Party Advisory, VDB Entry |
| Zeta Components Mail CVE-2017-15806 Arbitrary Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Site not found · GitHub Pages | af854a3a-2127-422b-91ae-364da2661108 | kay-malwarebenchmark.github.io | Issue Tracking, Third Party Advisory |
| Release Mail 1.8.2 released · zetacomponents/Mail · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Issue Tracking, Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.