CVE Database · CVE-2016-10034
CVSS v3.1
N/A
EPSS
38.44%
Published
Dec 30, 2016
Modified
May 6, 2026
Public PoC / Exploit (4)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
Weaknesses (CWE)
Affected Products (10)
References (16)