CVE-2008-5619
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 58.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 58.64% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- roundcube/webmail
- Source
- cve@mitre.org
References
- http://mahara.org/interaction/forum/topic.php?id=533
- http://osvdb.org/53893
- http://secunia.com/advisories/33145
- http://secunia.com/advisories/33170Vendor Advisory
- http://secunia.com/advisories/34789
- http://sourceforge.net/forum/forum.php?forum_id=898542Vendor Advisory
- http://trac.roundcube.net/changeset/2148Exploit
- http://trac.roundcube.net/ticket/1485618Exploit
- http://www.openwall.com/lists/oss-security/2008/12/12/1
- http://www.securityfocus.com/archive/1/499489/100/0/threaded
- http://www.vupen.com/english/advisories/2008/3418
- http://www.vupen.com/english/advisories/2008/3419
- https://github.com/PHPMailer/PHPMailer/commit/8beacc646acb67c995aea10ac5585970efc7355a
- https://www.exploit-db.com/exploits/7549
- https://www.exploit-db.com/exploits/7553
- https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00783.html
- https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00802.html
- http://mahara.org/interaction/forum/topic.php?id=533
- http://osvdb.org/53893
- http://secunia.com/advisories/33145
- http://secunia.com/advisories/33170Vendor Advisory
- http://secunia.com/advisories/34789
- http://sourceforge.net/forum/forum.php?forum_id=898542Vendor Advisory
- http://trac.roundcube.net/changeset/2148Exploit
- http://trac.roundcube.net/ticket/1485618Exploit
- http://www.openwall.com/lists/oss-security/2008/12/12/1
- http://www.securityfocus.com/archive/1/499489/100/0/threaded
- http://www.vupen.com/english/advisories/2008/3418
- http://www.vupen.com/english/advisories/2008/3419
- https://github.com/PHPMailer/PHPMailer/commit/8beacc646acb67c995aea10ac5585970efc7355a
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.