SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-1032

Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.

HIGH 7.5EPSS 3.57%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.57% probability · 89th percentile
CISA KEV
Not listed
Affected
phprpc/phprpc
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.