{"id":"GHSA-8jc3-5p29-qgjx","summary":"PHPMailer Local file inclusion","details":"### Impact\nArbitrary local file inclusion via the `$lang` property, remotely exploitable if host application passes unfiltered user data into that property. The 3 CVEs listed are applications that used PHPMailer that were vulnerable to this problem.\n\n### Patches\nIt's not known exactly when this was fixed in the host applications, but it was fixed in PHPMailer 5.2.0.\n\n### Workarounds\nFilter and validate user-supplied data before use.\n\n### References\nhttps://nvd.nist.gov/vuln/detail/CVE-2006-5734\nhttps://nvd.nist.gov/vuln/detail/CVE-2007-3215\nhttps://nvd.nist.gov/vuln/detail/CVE-2007-2021\nExample exploit: https://www.exploit-db.com/exploits/14893\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open a private issue in [the PHPMailer project](https://github.com/PHPMailer/PHPMailer)","aliases":["CVE-2006-5734"],"modified":"2024-02-02T20:58:49.424373Z","published":"2024-02-02T20:43:57Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-02-02T20:43:57Z"},"references":[{"type":"WEB","url":"https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-8jc3-5p29-qgjx"},{"type":"PACKAGE","url":"https://github.com/PHPMailer/PHPMailer"}],"affected":[{"package":{"name":"phpmailer/phpmailer","ecosystem":"Packagist","purl":"pkg:composer/phpmailer/phpmailer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-8jc3-5p29-qgjx/GHSA-8jc3-5p29-qgjx.json"}}],"schema_version":"1.9.0"}