CVE-2016-10033 is a command argument injection vulnerability in PHPMailer before version 5.2.18. The flaw is in the mailSend function used by the isMail transport, where attacker-controlled input placed into the Sender property is incorporated into parameters passed to PHP's mail() function. Because the input is not safely neutralized, a crafted Sender value containing a backslash-double-quote sequence can break the intended argument structure and inject additional command-line options into the underlying mail transfer agent invocation. This allows a remote attacker to supply extra parameters beyond the intended sender envelope argument, potentially causing arbitrary program execution. The issue is a real-world example of CWE-88, improper neutralization of argument delimiters in a command.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (9 hidden).
Single-file Python exploit targeting CVE-2016-10033 in PHPMailer versions prior to 5.2.18. The script is a real exploit, not a detector: it crafts a multipart/form-data POST to a vulnerable contact form endpoint (/contact.php), abusing the email field to inject PHPMailer sendmail parameters. The injected parameters set a queue directory and force output to /var/www/html/bd1.php, effectively writing attacker-controlled PHP code into the web root. The PHP payload executes a Python reverse shell one-liner that connects to the hardcoded listener 192.168.2.76:4444 and spawns /bin/sh. After sending the malicious form, the script performs a GET request to the dropped backdoor (bd1.php) to trigger code execution. Repository structure is minimal: one Python file (40974.py) containing banner text, hardcoded target/lhost/backdoor configuration, payload construction, multipart form assembly, and the two HTTP requests used for exploitation. No framework is used, no modularization is present, and the payload is hardcoded, making this an operational but basic exploit.
This repository provides a proof-of-concept exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer versions up to 5.2.17. The exploit consists of a single Python script ('exploit.py') and a README.md file. The script targets a web application using PHPMailer with sendmail, sending a specially crafted POST request to a contact form endpoint ('http://raven.local/contact.php'). The payload abuses the $additional_parameters argument to inject a command that writes a PHP web shell ('/var/www/html/shell.php') to the server. The script then accesses this shell to trigger a reverse shell connection back to the attacker. The exploit requires the target to be vulnerable and accessible, and the attacker to have a listener set up to receive the shell. The repository is structured simply, with clear documentation and a single exploit script.
This repository is a proof-of-concept exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer (versions 5.2.0 to 5.2.21). The main exploit logic is implemented in 'script.py', a Python script that sends a specially crafted POST request to a vulnerable web application, exploiting PHPMailer's improper handling of email addresses to write a PHP webshell to the server (by default, to /var/www/{random}.php). The script then tests the backdoor and, if successful, provides an interactive shell for executing arbitrary commands on the compromised server via HTTP requests. The exploit supports options for proxying requests, customizing the backdoor path, and toggling output formatting. The repository also includes a README with usage instructions, a requirements.txt for dependencies, and standard project files. No hardcoded IPs or domains are present; the target is user-supplied. The exploit is operational, providing a working webshell if the target is vulnerable.
This repository contains a single Metasploit module: 'wp_phpmailer_host_header.rb', which exploits a command injection vulnerability (CVE-2016-10033) in WordPress 4.6 when used with Exim as the mail transfer agent. The exploit leverages a crafted Host header to inject commands via PHPMailer, which is bundled with WordPress. The module requires a valid WordPress username and targets the lost password functionality (wp-login.php?action=lostpassword). The exploit delivers a payload (default: linux/x64/meterpreter_reverse_https) using a command stager (wget or curl) and writes temporary files to a writable directory (default: /tmp). The attack vector is network-based, exploiting HTTP requests to the WordPress login endpoint. The module is weaponized, allowing for customizable payloads and is part of the Metasploit framework. The code is well-structured, with clear separation of initialization, exploitation, and utility methods.
This repository contains a single Metasploit module (phpmailer_arg_injection.rb) that exploits argument injection vulnerabilities in PHPMailer versions up to 5.2.19 (CVE-2016-10033 and CVE-2016-10045). The exploit works by injecting arguments into the sendmail binary via crafted email fields, allowing the attacker to write a PHP payload (webshell) to a writable directory (default: /var/www) on the target server. The module then triggers the payload via an HTTP GET request, resulting in remote code execution as the web server user. The module is configurable for the application root (TARGETURI), the web root (WEB_ROOT), and the payload trigger path (TRIGGERURI). The exploit is operational and provides a working webshell if the target is vulnerable and properly configured. The only file in the repository is a Ruby script designed for use within the Metasploit framework.
This repository provides a full exploit environment and operational exploit scripts for CVE-2016-10033, a remote code execution vulnerability in PHPMailer versions prior to 5.2.18. The repository includes a vulnerable Docker environment, the vulnerable PHPMailer source, and two main Bash exploit scripts: 'exploit.sh' and 'deface.sh'. - 'exploit.sh' targets a vulnerable web application, exploiting improper sanitization in PHPMailer to inject a malicious 'From' address that causes PHP's mail() function to write a web shell (backdoor.php) to the web root. The script then interacts with the shell via HTTP requests, allowing the attacker to execute arbitrary commands on the server. - 'deface.sh' uses a similar technique to overwrite the web root's index.php with attacker-supplied content, effectively defacing the site. The payload is a simple PHP web shell that executes base64-decoded commands supplied via the 'cmd' GET parameter. The exploit is network-based, requiring only HTTP access to the vulnerable application. The repository also contains the full PHPMailer source, language files, and example scripts, but the core exploit logic is in the Bash scripts and the described payload. Notable endpoints include the web shell at '/backdoor.php' and the defaced '/index.php'. The Dockerfile sets up a vulnerable environment for testing, exposing HTTP on port 80 and a fake SMTP server on port 25. This exploit is operational and provides a working shell on successful exploitation.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2016-10033, targeting WordPress 4.6.0 with Exim4 MTA installed. The structure includes a Dockerfile to set up a vulnerable WordPress environment, a docker-compose.yml for orchestration, a README.md with usage instructions, and the main exploit script 'wordpress-rce-exploit.sh'. The exploit works by abusing the PHPMailer vulnerability in WordPress to achieve remote code execution via a crafted Host header in a POST request to the lost password endpoint. The script serves a bash reverse shell payload, writes it to the target's /tmp directory, and then executes it, resulting in a reverse shell connection to the attacker's machine on TCP port 1337. The exploit does not require authentication and demonstrates a real-world attack scenario. The repository is operational and provides a working exploit with a functional payload.
This repository contains a Golang-based exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer versions prior to 5.2.18. The exploit consists of a single Go source file (main.go) and a README.md with usage instructions. The exploit works by sending a specially crafted HTTP POST request to a vulnerable web application using PHPMailer, attempting to upload a PHP web shell (<?php system($_GET[cmd]);?>) to a specified directory (default: /var/www/) on the target server. The tool first checks the target page for the presence of required form fields (email, subject, text), then proceeds with the exploit if they are found. The default target is 'http://target.com', but this can be changed via a command-line flag. If successful, the attacker can access the web shell via HTTP and execute arbitrary commands on the server. The repository is operational and provides a working exploit with a hardcoded payload.
This repository provides a complete environment and exploit for CVE-2016-10033, a remote code execution vulnerability in WordPress <= 4.6 via PHPMailer. The structure includes a Dockerfile to set up a vulnerable WordPress instance, configuration files, a SQL dump for pre-populated data, and scripts for exploitation. The main exploit script (wordpress-rce-exploit.sh) is a Bash script that automates the attack: it crafts malicious Host headers to exploit the PHPMailer vulnerability, writes a payload (reverse shell) to the target, and then executes it, resulting in a shell back to the attacker. The README provides detailed manual exploitation steps, including how to write arbitrary files (such as a webshell) and how to obtain a reverse shell. The exploit is operational, providing a working payload and automation, and is suitable for testing and demonstration purposes. The repository also includes a minimal PHP webshell for post-exploitation access. The main attack vector is network-based, targeting the WordPress login endpoint. Several fingerprintable endpoints are present, including the vulnerable login page, webshell location, and reverse shell listener. The repository is well-structured for both manual and automated exploitation of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A historical precedent cited for argument injection in a mail processing function enabling file write and program execution.
A critical PHPMailer command injection issue enabling remote unauthenticated attackers to achieve arbitrary code execution in the web server context (affecting PHPMailer versions prior to 5.2.18).
Argument injection in PHPMailer’s use of PHP mail() that can enable file write and program execution via technically valid email-address input.
Argument injection vulnerability in PHPMailer mail-processing that allows technically valid email addresses to inject additional mail() parameters, enabling file write and program execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.