← Vulnerability feed

Vulnerability record · CVE-2016-10034 · published 30 December 2016

CVE-2016-10034: Zend framework command injection vulnerability

Zend · Zend Framework

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.

9.8 CVSS 3.0 Critical EPSS 38% · top 1.5% CWE-77 · Command injection
9.8CVSS 3.0 base score, v2 7.5
38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-10034 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-29312Zend framework deserialization of untrusted data vulnerabilityAn issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be…EPSS 1.3%9.8CVE-2021-3007Laminas-http and Zend Framework PHP deserialization RCELaminas-http before 2.14.2 and Zend Framework 3.0.0 contain a PHP object deserialization flaw tied to the __destruct method of Zend\Http\Response\Str…EPSS 75%analysed9.8CVE-2014-8089Zend framework sql injection vulnerabilitySQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …EPSS 2.6%9.8CVE-2011-1939Zend framework sql injection vulnerabilitySQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction …EPSS 3.9%9.8CVE-2014-4914Zend framework sql injection vulnerabilityThe Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…EPSS 2.3%9.8CVE-2016-4861Fedoraproject fedora sql injection vulnerabilityThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection atta…EPSS 4.1%9.8CVE-2016-6233Fedoraproject fedora sql injection vulnerabilityThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection atta…EPSS 2.0%9.8CVE-2015-7695Zend framework sql injection vulnerabilityThe PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL c…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2016-10034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.