Posted by Dawid Golunski on Dec 27
PHPMailer < 5.2.18 Remote Code Execution
CVE-2016-10033
Attaching an updated version of the advisory with more details + simple PoC.
Still incomplete. There will be more updates/exploits soon at:
https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html
and the feed: