vendor:
Roundcube Webmail
by:
Hunger
7.5
CVSS
HIGH
html2text.php / preg_replace() / eval bug
95
CWE
Product Name: Roundcube Webmail
Affected Version From: 0.2-beta
Affected Version To: 0.2-beta
Patch Exists: YES
Related CWE: CVE-2008-5619
CPE: a:roundcube:roundcube_webmail
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2008
Exploit for Roundcube Webmail =< 0.2-beta
This exploit is for Roundcube Webmail version 0.2-beta and below. It is a vulnerability in the html2text.php file, which is vulnerable to a preg_replace() / eval bug. The exploit allows an attacker to execute arbitrary PHP code on the vulnerable system.
Mitigation:
Upgrade to the latest version of Roundcube Webmail.