CVE-2005-2498
Last modified
CVE-2005-2498 is a vulnerability of currently unknown severity. Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.. EPSS estimates a 5.09% chance of exploitation in the next 30 days.
Description
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gggeek | Phpxmlrpc | <= 1.1.1 |
| Debian | Debian Linux | 3.1 |
References
- http://marc.info/?l=bugtraq&m=112412415822890&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112431497300344&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112605112027335&w=2Third Party Advisory
- http://secunia.com/advisories/16431Broken Link
- http://secunia.com/advisories/16432Broken Link
- http://secunia.com/advisories/16441Broken Link
- http://secunia.com/advisories/16460Broken Link
- http://secunia.com/advisories/16465Broken Link
- http://secunia.com/advisories/16468Broken Link
- http://secunia.com/advisories/16469Broken Link
- http://secunia.com/advisories/16491Broken Link
- http://secunia.com/advisories/16550Broken Link
- http://secunia.com/advisories/16558Broken Link
- http://secunia.com/advisories/16563Broken Link
- http://secunia.com/advisories/16619Broken Link
- http://secunia.com/advisories/16635Broken Link
- http://secunia.com/advisories/16693Broken Link
- http://secunia.com/advisories/16976Broken Link
- http://secunia.com/advisories/17053Broken Link
- http://secunia.com/advisories/17066Broken Link
- http://secunia.com/advisories/17440Broken Link
- http://www.debian.org/security/2005/dsa-789Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-798Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-840Mailing List
- http://www.debian.org/security/2005/dsa-842Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200509-19.xmlThird Party Advisory
- http://www.hardened-php.net/advisory_152005.67.htmlNot Applicable, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/408125Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/14560Broken Link, Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=112412415822890&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112431497300344&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=112605112027335&w=2Third Party Advisory
- http://secunia.com/advisories/16431Broken Link
- http://secunia.com/advisories/16432Broken Link
- http://secunia.com/advisories/16441Broken Link
- http://secunia.com/advisories/16460Broken Link
- http://secunia.com/advisories/16465Broken Link
- http://secunia.com/advisories/16468Broken Link
- http://secunia.com/advisories/16469Broken Link
- http://secunia.com/advisories/16491Broken Link
- http://secunia.com/advisories/16550Broken Link
- http://secunia.com/advisories/16558Broken Link
- http://secunia.com/advisories/16563Broken Link
- http://secunia.com/advisories/16619Broken Link
- http://secunia.com/advisories/16635Broken Link
- http://secunia.com/advisories/16693Broken Link
- http://secunia.com/advisories/16976Broken Link
- http://secunia.com/advisories/17053Broken Link
- http://secunia.com/advisories/17066Broken Link
- http://secunia.com/advisories/17440Broken Link
- http://www.debian.org/security/2005/dsa-789Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-798Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-840Mailing List
- http://www.debian.org/security/2005/dsa-842Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200509-19.xmlThird Party Advisory
- http://www.hardened-php.net/advisory_152005.67.htmlNot Applicable, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/408125Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/14560Broken Link, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-2498?
How severe is CVE-2005-2498?
How do I fix CVE-2005-2498?
Are you affected by CVE-2005-2498?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
