On Tue, 9 May 2017, admin@??? wrote:
> https://bugs.exim.org/show_bug.cgi?id=2118
>
> Jasen Betts <jasen@???> changed:
>
> What |Removed |Added
> ----------------------------------------------------------------------------
> CC| |jasen@???
>
> --- Comment #7 from Jasen Betts <jasen@???> ---
> It looks to me like a "shell injection" flaw in wordpress.
Yes, but exim provides a language for the hacker to
modify the command after wordpress has sanitised it :-(
--
Andrew C Aitchison Cambridge, UK