Back

HIGH

security flaw

Published Jul 1, 2005

Description

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (54)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 1, 2005
Updated Aug 7, 2024
Reserved Jun 8, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jun 29, 2005