monty2210 Posted October 1, 2019 Share Posted October 1, 2019 Sorry for my English use translator today going on antivirus in plesk i found this Public Vulnerabilities File /vendor/phpmailer/phpmailer/src/PHPMailer.php Vulnerability RCE : CVE-2016-10045, CVE-2016-10031 and I don't know if it's false positive or I have a problem Could you guide me a little? Regards Fernando 0 Quote Link to comment Share on other sites More sharing options...
monty2210 Posted October 1, 2019 Author Share Posted October 1, 2019 He left the file PHPMailer.php 0 Quote Link to comment Share on other sites More sharing options...
Remitur Posted October 2, 2019 Share Posted October 2, 2019 (edited) It seems to affect only phpmailer < 5.2.20: what version are you using? Just update it and maybe you'll fix it... https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html Edited October 2, 2019 by Remitur 0 Quote Link to comment Share on other sites More sharing options...
bear Posted October 2, 2019 Share Posted October 2, 2019 (edited) 17 hours ago, monty2210 said: File /vendor/phpmailer/phpmailer/src/PHPMailer.php The folder "src", and the file named doesn't exist in my installations. Can you show the file structure for that directory tree? Edited October 2, 2019 by bear 0 Quote Link to comment Share on other sites More sharing options...
brian! Posted October 2, 2019 Share Posted October 2, 2019 2 hours ago, bear said: Can you show the file structure for that directory tree? the src folder was seemingly only introduced with v7.8, so if you haven't updated, then that could be why you can't see it. 0 Quote Link to comment Share on other sites More sharing options...
monty2210 Posted October 2, 2019 Author Share Posted October 2, 2019 hello, sorry for late, work I have the latest official downloaded version with key left structure 0 Quote Link to comment Share on other sites More sharing options...
bear Posted October 2, 2019 Share Posted October 2, 2019 That must be why. I generally hold off until the dust settles and the issues get resolved. Still waiting. 😉 0 Quote Link to comment Share on other sites More sharing options...
monty2210 Posted October 4, 2019 Author Share Posted October 4, 2019 if I take PHPMailer.php from the official zip I pass it through https://www.virustotal.com this comes out 0 Quote Link to comment Share on other sites More sharing options...
monty2210 Posted October 4, 2019 Author Share Posted October 4, 2019 whmcs_v782_full 0 Quote Link to comment Share on other sites More sharing options...
monty2210 Posted October 10, 2019 Author Share Posted October 10, 2019 well, according to support it is a false positive 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.