CVE-2008-5619

Chuggnutt HTML to Text Converter <5.2.10 - RCE

Title source: llm

Description

html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Hunger · bashwebappsphp
https://www.exploit-db.com/exploits/7553
exploitdb WORKING POC VERIFIED
by Jacobo Avariento · textwebappsphp
https://www.exploit-db.com/exploits/7549

Scores

EPSS 0.7769
EPSS Percentile 99.0%

Details

CWE
CWE-94
Status published
Products (3)
phpmailer/phpmailer 0 - 5.2.10Packagist
roundcube/webmail 0.2.1 alpha
roundcube/webmail 0.2.3 beta
Published Dec 17, 2008
Tracked Since Feb 18, 2026