VDB

CVE-2005-1921

CVE-2005-1921 PUBLISHED KEV CVSS 7.5 HIGH

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

EPSS 86.15% · 99.4th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
86.15%
99.4th percentile

Affected Products

VendorProductVersions
drupaldrupal0, 4.6.0
gggeekphpxmlrpc0
tikitikiwiki_cms\/groupware0
n/an/an/a
debiandebian_linux3.1
phpxml_rpc0

Timeline

  • Jul 1, 2005 CVE Published
  • Jul 25, 2010 PoC Published
  • Jul 30, 2010 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score

References

…and 31 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›