CVE-2005-2498
Last modified
CVE-2005-2498 is a vulnerability of currently unknown severity. Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.. EPSS estimates a 5.09% chance of exploitation in the next 30 days.
Description
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gggeek | Phpxmlrpc | <= 1.1.1 |
| Debian | Debian Linux | 3.1 |
References
- http://marc.info/?l=bugtraq&m=112412415822890&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112431497300344&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112605112027335&w=2Third Party Advisory
- http://secunia.com/advisories/16431Broken Link
- http://secunia.com/advisories/16432Broken Link
- http://secunia.com/advisories/16441Broken Link
- http://secunia.com/advisories/16460Broken Link
- http://secunia.com/advisories/16465Broken Link
- http://secunia.com/advisories/16468Broken Link
- http://secunia.com/advisories/16469Broken Link
- http://secunia.com/advisories/16491Broken Link
- http://secunia.com/advisories/16550Broken Link
- http://secunia.com/advisories/16558Broken Link
- http://secunia.com/advisories/16563Broken Link
- http://secunia.com/advisories/16619Broken Link
- http://secunia.com/advisories/16635Broken Link
- http://secunia.com/advisories/16693Broken Link
- http://secunia.com/advisories/16976Broken Link
- http://secunia.com/advisories/17053Broken Link
- http://secunia.com/advisories/17066Broken Link
- http://secunia.com/advisories/17440Broken Link
- http://www.debian.org/security/2005/dsa-789Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-798Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-840Mailing List
- http://www.debian.org/security/2005/dsa-842Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200509-19.xmlThird Party Advisory
- http://www.hardened-php.net/advisory_152005.67.htmlNot Applicable, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/408125Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/14560Broken Link, Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=112412415822890&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112431497300344&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112605112027335&w=2Third Party Advisory
- http://secunia.com/advisories/16431Broken Link
- http://secunia.com/advisories/16432Broken Link
- http://secunia.com/advisories/16441Broken Link
- http://secunia.com/advisories/16460Broken Link
- http://secunia.com/advisories/16465Broken Link
- http://secunia.com/advisories/16468Broken Link
- http://secunia.com/advisories/16469Broken Link
- http://secunia.com/advisories/16491Broken Link
- http://secunia.com/advisories/16550Broken Link
- http://secunia.com/advisories/16558Broken Link
- http://secunia.com/advisories/16563Broken Link
- http://secunia.com/advisories/16619Broken Link
- http://secunia.com/advisories/16635Broken Link
- http://secunia.com/advisories/16693Broken Link
- http://secunia.com/advisories/16976Broken Link
- http://secunia.com/advisories/17053Broken Link
- http://secunia.com/advisories/17066Broken Link
- http://secunia.com/advisories/17440Broken Link
- http://www.debian.org/security/2005/dsa-789Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-798Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-840Mailing List
- http://www.debian.org/security/2005/dsa-842Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200509-19.xmlThird Party Advisory
- http://www.hardened-php.net/advisory_152005.67.htmlNot Applicable, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/408125Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/14560Broken Link, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-2498?
How severe is CVE-2005-2498?
How do I fix CVE-2005-2498?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-2492The raw_sendmsg function in the Linux kernel 2.6 before 2.6.…
- CVE-2005-2493Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2005-2494kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to ga…
- CVE-2005-2495Multiple integer overflows in XFree86 before 4.3.0 allow use…
- CVE-2005-2496The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the…
- CVE-2005-2497Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2005-2499slocate before 2.7 does not properly process very long paths…
- CVE-2005-2500Buffer overflow in the xdr_xcode_array2 function in xdr.c in…
- CVE-2005-2501Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 all…
- CVE-2005-2502Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as…
- CVE-2005-2503AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with …
- CVE-2005-2504The System Profiler in Mac OS X 10.4.2 labels a Bluetooth de…
Are you affected by CVE-2005-2498?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
