CVE-2008-5619: Code Injection
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the pregreplace function with the eval switch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5619?
CVE-2008-5619 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-5619?
To fix CVE-2008-5619, update PHPMailer to version 5.2.10 or later, or upgrade to the latest version of the affected software.
Which software is affected by CVE-2008-5619?
CVE-2008-5619 affects PHPMailer prior to 5.2.10, RoundCube versions 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03.
What type of attack does CVE-2008-5619 involve?
CVE-2008-5619 involves remote code execution attacks through crafted input processed by the preg_replace function.
Is CVE-2008-5619 still a relevant vulnerability?
While CVE-2008-5619 was disclosed in 2008, it remains relevant for systems running outdated versions of the affected software.