---
cve: "CVE-2008-5619"
severity: "LOW"
cvss: 3.1
epss: "58.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2008-12-17 02:30:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T04:38:10+02:00"
---

# CVE-2008-5619

> 3.1 LOW · 🧪 PoC

## Beschreibung

html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.

## Exploit-Evidenz

- [EDB-7549 — Roundcube Webmail 0.2-3 Beta - Code Execution](https://www.exploit-db.com/exploits/7549) ✅
- [EDB-7553 — Roundcube Webmail 0.2b - Remote Code Execution](https://www.exploit-db.com/exploits/7553) ✅

## Referenzen

- <http://mahara.org/interaction/forum/topic.php?id=533>
- <https://www.exploit-db.com/exploits/7549>
- <https://www.exploit-db.com/exploits/7553>
- <https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00802.html>
- <http://www.vupen.com/english/advisories/2008/3418>
- <https://github.com/PHPMailer/PHPMailer/commit/8beacc646acb67c995aea10ac5585970efc7355a>
- <http://trac.roundcube.net/changeset/2148>
- <http://osvdb.org/53893>
- <http://sourceforge.net/forum/forum.php?forum_id=898542>
- <http://secunia.com/advisories/34789>
- <http://www.vupen.com/english/advisories/2008/3419>
- <http://trac.roundcube.net/ticket/1485618>
- <https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00783.html>
- <http://www.openwall.com/lists/oss-security/2008/12/12/1>
- <http://secunia.com/advisories/33170>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2008-5619) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
