VYPR
High severityNVD Advisory· Published Dec 17, 2008· Updated Apr 23, 2026

CVE-2008-5619

CVE-2008-5619

Description

html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
phpmailer/phpmailerPackagist
< 5.2.105.2.10

Affected products

2
  • Roundcube/Webmail2 versions
    cpe:2.3:a:roundcube:webmail:0.2.1:alpha:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:roundcube:webmail:0.2.1:alpha:*:*:*:*:*:*
    • cpe:2.3:a:roundcube:webmail:0.2.3:beta:*:*:*:*:*:*

Patches

1
8beacc646acb

Add security notices

https://github.com/PHPMailer/PHPMailerMarcus BointonJul 22, 2016via ghsa
1 file changed · +8 0
  • README.md+8 0 modified
    @@ -139,6 +139,14 @@ Build status: [![Build Status](https://travis-ci.org/PHPMailer/PHPMailer.svg)](h
     
     If this isn't passing, is there something you can do to help?
     
    +## Security
    +
    +Please follow responsible disclosure - report any security problems found to the maintainers privately.
    +
    +PHPMailer versions prior to 5.2.14 (released November 2015) are vulnerable to [CVE-2015-8476](https://web.nvd.nist.gov/view/vuln/detail?vulnId=) an SMTP injection bug.
    +
    +PHPMailer versions prior to 5.2.10 (released May 2015) are vulnerable to [CVE-2008-5619](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5619), a remote code execution vulnerability in the bundled html2text library. This file was removed in 5.2.10, so if you are using a version prior to that and make use of the html2text function, it's vitally important that you upgrade and remove this file.
    +
     ## Contributing
     
     Please submit bug reports, suggestions and pull requests to the [GitHub issue tracker](https://github.com/PHPMailer/PHPMailer/issues).
    

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

19

News mentions

0

No linked articles in our index yet.