by axew3 » Tue Dec 27, 2016 8:19 am
- CVE-2016-10033
- Release date: 25.12.2016
- Revision 1.0
- Severity: Critical
registrations disabled on WordPress side, due to a vulnerability on
PHPMailer < 5.2.18 Remote Code Execution.
WordPress, even on latest 4.7, come with version PHPMailer 5.2.14, so if you own a WordPress based site, or a site based on a CMS that embed and use PHPMailer, you should DO THE SAME, and at least disable registrations and contact forms until a security patch has not been released!
https://legalhackers.com/advisories/PHP ... -Vuln.html
"Probably the world's most popular code for sending email from PHP!
Used by many open-source projects: WordPress, Drupal, 1CRM, SugarCRM, Yii,
Joomla! and many more"
p.s but you can register here in phpBB side:
phpBB not use PHPmailer, so has not been temporary disabled.
[quote]- CVE-2016-10033
- Release date: 25.12.2016
- Revision 1.0
- Severity: Critical[/quote]
registrations disabled on WordPress side, due to a vulnerability on
[size=130][b]PHPMailer < 5.2.18 Remote Code Execution.
WordPress, even on latest 4.7, come with version PHPMailer 5.2.14, so if you own a WordPress based site, or a site based on a CMS that embed and use PHPMailer, you should DO THE SAME, and at least disable registrations and contact forms until a security patch has not been released!
https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html[/b][/size]
[quote]
"Probably the world's most popular code for sending email from PHP!
Used by many open-source projects: WordPress, Drupal, 1CRM, SugarCRM, Yii,
Joomla! and many more"[/quote]
p.s but you can register here in phpBB side: [b]phpBB not use PHPmailer, so has not been temporary disabled.[/b]