CVE-2015-8476

Source
https://cve.org/CVERecord?id=CVE-2015-8476
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2015-8476.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2015-8476
Aliases
Downstream
Withdrawn
2026-01-27T04:15:13Z
Published
2015-12-16T21:59:05Z
Modified
2026-04-16T01:47:51Z
Summary
[none]
Details

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.

References

Affected packages