html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer prior to 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote malicious users to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
roundcube webmail 0.2.1 |
||
roundcube webmail 0.2.3 |