CVE-2005-2498
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.09% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- gggeek/phpxmlrpc · debian/debian linux
- Source
- secalert@redhat.com
References
- http://marc.info/?l=bugtraq&m=112412415822890&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112431497300344&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112605112027335&w=2Third Party Advisory
- http://secunia.com/advisories/16431Broken Link
- http://secunia.com/advisories/16432Broken Link
- http://secunia.com/advisories/16441Broken Link
- http://secunia.com/advisories/16460Broken Link
- http://secunia.com/advisories/16465Broken Link
- http://secunia.com/advisories/16468Broken Link
- http://secunia.com/advisories/16469Broken Link
- http://secunia.com/advisories/16491Broken Link
- http://secunia.com/advisories/16550Broken Link
- http://secunia.com/advisories/16558Broken Link
- http://secunia.com/advisories/16563Broken Link
- http://secunia.com/advisories/16619Broken Link
- http://secunia.com/advisories/16635Broken Link
- http://secunia.com/advisories/16693Broken Link
- http://secunia.com/advisories/16976Broken Link
- http://secunia.com/advisories/17053Broken Link
- http://secunia.com/advisories/17066Broken Link
- http://secunia.com/advisories/17440Broken Link
- http://www.debian.org/security/2005/dsa-789Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-798Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-840Mailing List
- http://www.debian.org/security/2005/dsa-842Mailing List, Third Party Advisory
- http://www.fedoralegacy.org/updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.htmlBroken Link
- http://www.gentoo.org/security/en/glsa/glsa-200509-19.xmlThird Party Advisory
- http://www.hardened-php.net/advisory_152005.67.htmlNot Applicable, Patch, Vendor Advisory
- http://www.novell.com/linux/security/advisories/2005_49_php.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-748.htmlBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.