CVE-2008-5619
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
- Affected products
- Atmail Open, Chuggnutt Html To Text Converter, Mahara, Phpmailer, Roundcube Webmail
- Roundcube Webmail
- = 0.2.1, 0.2.3
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 58.6% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2008-12-17
CVE-2008-5619 at NVD
14 known exploits for CVE-2008-5619
Proof-of-concept code and exploit modules indexed by Sploitus
RoundCube Webmail <= 0.2-3 beta Code Execution Vulnerability
RoundCube Webmail <= 0.2b Remote Code Execution Exploit
Roundcube 0.2beta RCE
RoundCube Webmail 0.2b Remote Code Execution
RoundCube Webmail 0.2-3 Beta Code Execution
RoundCube Webmail <= 0.2b Remote Code Execution Exploit
RoundCube Webmail <= 0.2-3 beta Code Execution Vulnerability
Roundcube Webmail 0.2-3 Beta - Code Execution
Roundcube Webmail 0.2b - Remote Code Execution
RoundCube Webmail <= 0.2b Remote Code Execution Exploit
RoundCube Webmail <= 0.2-3 beta Code Execution Vulnerability
Roundcube Webmail 0.2b - Remote Code Execution
Roundcube Webmail 0.2-3 Beta - Code Execution
Immunity Canvas: ROUNDCUBE