{"id":"CVE-2006-5734","aliases":[],"url":"https://o3.security/vulnerability/CVE-2006-5734","summary":"PHPMailer Local file inclusion","details":"### Impact\nArbitrary local file inclusion via the `$lang` property, remotely exploitable if host application passes unfiltered user data into that property. The 3 CVEs listed are applications that used PHPMailer that were vulnerable to this problem.\n\n### Patches\nIt's not known exactly when this was fixed in the host applications, but it was fixed in PHPMailer 5.2.0.\n\n### Workarounds\nFilter and validate user-supplied data before use.\n\n### References\nhttps://nvd.nist.gov/vuln/detail/CVE-2006-5734\nhttps://nvd.nist.gov/vuln/detail/CVE-2007-3215\nhttps://nvd.nist.gov/vuln/detail/CVE-2007-2021\nExample exploit: https://www.exploit-db.com/exploits/14893\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open a private issue in [the PHPMailer project](https://github.com/PHPMailer/PHPMailer)","published":"2024-02-02T20:43:57Z","modified":"2024-02-02T20:58:49.424373Z","cvss":null,"epss":{"score":0.01435,"percentile":0.71065,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"phpmailer/phpmailer","fixedVersion":"5.2.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-8jc3-5p29-qgjx"},{"type":"PACKAGE","url":"https://github.com/PHPMailer/PHPMailer"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-02T20:58:49.424373Z"}}