CVE-2008-5619
CVE-2008-5619
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
Productos afectados
n/a · n/aPoCs públicas encontradas — 2
cve_referencewww.exploit-db.com/exploits/7549no verificadocve_referencewww.exploit-db.com/exploits/7553no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://mahara.org/interaction/forum/topic.php?id=533http://osvdb.org/53893http://secunia.com/advisories/33145http://secunia.com/advisories/33170http://secunia.com/advisories/34789https://github.com/PHPMailer/PHPMailer/commit/8beacc646acb67c995aea10ac5585970efc7355ahttp://sourceforge.net/forum/forum.php?forum_id=898542https://www.exploit-db.com/exploits/7549https://www.exploit-db.com/exploits/7553https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00783.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-December/msg00802.htmlhttp://trac.roundcube.net/changeset/2148