CVE-2007-3215
PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
Date published : 2007-06-14
http://www.securityfocus.com/bid/24417
http://www.securityfocus.com/archive/1/471065/100/0/threaded