html2text.php: arbitrary code execution
| Package(s): | html2text.php |
CVE #(s): | CVE-2008-5619
|
| Created: | June 25, 2009 |
Updated: | July 1, 2009 |
| Description: |
html2text.php has a arbitrary code execution vulnerability.
From the National Vulnerability Database
entry:
html2text.php in Chuggnutt HTML to Text Converter, as used in RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch. |
| Alerts: |
|