mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
1.1 KiB
1.1 KiB
CVE-2008-5619
Description
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
POC
Reference
Github
- https://github.com/JamesYoungZhu/Practise
- https://github.com/clients1/mailer
- https://github.com/jatin-dwebguys/PHPMailer
- https://github.com/mitraxsou/radiant
- https://github.com/rosauceda/PHPMAILER1
- https://github.com/rosauceda/phpMail
- https://github.com/webworksinc/PHPMailer
- https://github.com/wking07/pmailer