{"api_version":"1","generated_at":"2026-07-23T12:25:27+00:00","cve":"CVE-2017-15806","urls":{"html":"https://cve.report/CVE-2017-15806","api":"https://cve.report/api/cve/CVE-2017-15806.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-15806","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-15806"},"summary":{"title":"CVE-2017-15806","description":"The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing \"-X/path/to/wwwroot/file.php.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2017-11-15 16:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.1","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://github.com/zetacomponents/Mail/issues/58","name":"https://github.com/zetacomponents/Mail/issues/58","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"","mime":"text/plain","httpstatus":"404","archivestatus":"404"},{"url":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/","name":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Site not found · GitHub Pages","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.exploit-db.com/exploits/43155/","name":"https://www.exploit-db.com/exploits/43155/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory","VDB Entry"],"title":"Zeta Components Mail 1.8.1 - Remote Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/101866","name":"http://www.securityfocus.com/bid/101866","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Zeta Components Mail CVE-2017-15806 Arbitrary Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/","name":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Site not found · GitHub Pages","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://github.com/zetacomponents/Mail/releases/tag/1.8.2","name":"https://github.com/zetacomponents/Mail/releases/tag/1.8.2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Release Notes","Third Party Advisory"],"title":"Release Mail 1.8.2 released · zetacomponents/Mail · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-15806","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15806","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"15806","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zetacomponents","cpe5":"mail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"15806","cve":"CVE-2017-15806","epss":"0.164570000","percentile":"0.949450000","score_date":"2026-05-13","updated_at":"2026-05-14 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T20:04:50.350Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"43155","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/43155/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/zetacomponents/Mail/issues/58"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/zetacomponents/Mail/releases/tag/1.8.2"},{"name":"101866","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/101866"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-11-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing \"-X/path/to/wwwroot/file.php.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-18T10:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"43155","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/43155/"},{"tags":["x_refsource_MISC"],"url":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/"},{"tags":["x_refsource_MISC"],"url":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/zetacomponents/Mail/issues/58"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/zetacomponents/Mail/releases/tag/1.8.2"},{"name":"101866","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/101866"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-15806","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing \"-X/path/to/wwwroot/file.php.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"43155","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/43155/"},{"name":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/","refsource":"MISC","url":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-critical-rce-vulnerability/"},{"name":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/","refsource":"MISC","url":"https://kay-malwarebenchmark.github.io/blog/cve-2017-15806-yuan-cheng-dai-ma-zhi-xing-lou-dong/"},{"name":"https://github.com/zetacomponents/Mail/issues/58","refsource":"CONFIRM","url":"https://github.com/zetacomponents/Mail/issues/58"},{"name":"https://github.com/zetacomponents/Mail/releases/tag/1.8.2","refsource":"CONFIRM","url":"https://github.com/zetacomponents/Mail/releases/tag/1.8.2"},{"name":"101866","refsource":"BID","url":"http://www.securityfocus.com/bid/101866"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-15806","datePublished":"2017-11-15T16:00:00.000Z","dateReserved":"2017-10-23T00:00:00.000Z","dateUpdated":"2024-08-05T20:04:50.350Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-15 16:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:zetacomponents:mail:*:*:*:*:*:*:*:*","versionEndExcluding":"1.8.2","matchCriteriaId":"927EE589-CA16-4708-B79F-DD7881B590F6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"15806","Ordinal":"1","Title":"CVE-2017-15806","CVE":"CVE-2017-15806","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"15806","Ordinal":"1","NoteData":"The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing \"-X/path/to/wwwroot/file.php.\"","Type":"Description","Title":"CVE-2017-15806"},{"CveYear":"2017","CveId":"15806","Ordinal":"2","NoteData":"2017-11-15","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"15806","Ordinal":"3","NoteData":"2017-11-18","Type":"Other","Title":"Modified"}]}}}