PHPMailer/SwiftMailer/ZendFramework Video PoC Exploit

PHPMailer < 5.2.18 Remote Code Execution (CVE-2016-10033)

PHPMailer < 5.2.20 Remote Code Execution (CVE-2016-10045)

SwiftMailer <= 5.4.5-DEV Remote Code Execution (CVE-2016-10074)

Zend Framework / zend-mail < 2.4.11 - Remote Code Execution (CVE-2016-10034)

Discovered by Dawid Golunski


The video below demonstrates how an attacker could potentially compromise a website (achieve remote code execution) by exploiting one of the vulnerabilities linked above in a web application (Contact Form) implemented with the use of: PHPMailer, Zend Framework (zend-mail) and SwiftMailer.
The video focuses on PHPMailer however the attack flow is common for each of the affected frameworks/libraries.

Exploit shown in the video can be downloaded from: PHPMailer/SwiftMailer/Zend-mail exploit

