High severityNVD Advisory· Published Dec 17, 2008· Updated Apr 23, 2026
CVE-2008-5619
CVE-2008-5619
Description
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
phpmailer/phpmailerPackagist | < 5.2.10 | 5.2.10 |
Affected products
2Patches
18beacc646acbAdd security notices
1 file changed · +8 −0
README.md+8 −0 modified@@ -139,6 +139,14 @@ Build status: [](h If this isn't passing, is there something you can do to help? +## Security + +Please follow responsible disclosure - report any security problems found to the maintainers privately. + +PHPMailer versions prior to 5.2.14 (released November 2015) are vulnerable to [CVE-2015-8476](https://web.nvd.nist.gov/view/vuln/detail?vulnId=) an SMTP injection bug. + +PHPMailer versions prior to 5.2.10 (released May 2015) are vulnerable to [CVE-2008-5619](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5619), a remote code execution vulnerability in the bundled html2text library. This file was removed in 5.2.10, so if you are using a version prior to that and make use of the html2text function, it's vitally important that you upgrade and remove this file. + ## Contributing Please submit bug reports, suggestions and pull requests to the [GitHub issue tracker](https://github.com/PHPMailer/PHPMailer/issues).
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
19- trac.roundcube.net/changeset/2148nvdExploitWEB
- trac.roundcube.net/ticket/1485618nvdExploitWEB
- secunia.com/advisories/33170nvdVendor Advisory
- sourceforge.net/forum/forum.phpnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-v5c9-mmw9-829qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2008-5619ghsaADVISORY
- mahara.org/interaction/forum/topic.phpnvdWEB
- osvdb.org/53893nvdWEB
- www.openwall.com/lists/oss-security/2008/12/12/1nvdWEB
- github.com/PHPMailer/PHPMailer/commit/8beacc646acb67c995aea10ac5585970efc7355anvdWEB
- www.exploit-db.com/exploits/7549nvdWEB
- www.exploit-db.com/exploits/7553nvdWEB
- www.redhat.com/archives/fedora-package-announce/2008-December/msg00783.htmlnvdWEB
- www.redhat.com/archives/fedora-package-announce/2008-December/msg00802.htmlnvdWEB
- secunia.com/advisories/33145nvd
- secunia.com/advisories/34789nvd
- www.securityfocus.com/archive/1/499489/100/0/threadednvd
- www.vupen.com/english/advisories/2008/3418nvd
- www.vupen.com/english/advisories/2008/3419nvd
News mentions
0No linked articles in our index yet.