VDB
CVE-2005-1921
CVE-2005-1921
PUBLISHED
KEV
CVSS 7.5 HIGH
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
EPSS 86.15% · 99.4th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
86.15%
99.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| drupal | drupal | 0, 4.6.0 |
| gggeek | phpxmlrpc | 0 |
| tiki | tikiwiki_cms\/groupware | 0 |
| n/a | n/a | n/a |
| debian | debian_linux | 3.1 |
| php | xml_rpc | 0 |
Timeline
- Jul 1, 2005 CVE Published
- Jul 25, 2010 PoC Published
- Jul 30, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- oval:org.mitre.oval:def:350 vdb
- DSA-789 vendor-advisory
- 15947 third-party-advisory
- 15852 third-party-advisory
- 15944 third-party-advisory
- SUSE-SR:2005:018 vendor-advisory
- 15883 third-party-advisory
- 15872 third-party-advisory
- 15895 third-party-advisory
- oval:org.mitre.oval:def:11294 vdb
- 1015336 vdb
- DSA-746 vendor-advisory
- 17674 third-party-advisory
- http://www.gulftech.org/?node=research&article_id=00087-07012005 url
- ADV-2005-2827 vdb
- 15917 third-party-advisory
- DSA-747 vendor-advisory
- SUSE-SA:2005:041 vendor-advisory
- http://www.hardened-php.net/advisory-022005.php url
- SSRT051069 vendor-advisory
…and 31 more