1 Video for CVE-2016-10033: PHPMailer RCE

PRO
Tier
difficulty_medium_icon
Medium
clock icon
< 1 Hr.
number of users completed icon
3721
badge icon
Yellow Badge
image of exercise CVE-2016-10033: Exploitation
play btn
Access to videos for this exercise is only available with PentesterLab PRO GOPRO
Spoiler
CVE-2016-10033: Exploitation

In this video, we explore the CVE-2016-10033 vulnerability found in PHPMailer, which allows attackers to execute arbitrary code by injecting extra parameters into the sendmail command. We demonstrate how to exploit this vulnerability to create a PHP file in the web root of the server and execute commands through a simple web shell.

video duration icon04:15 number of views icon3806