VDB
CVE-2005-2498
CVE-2005-2498
PUBLISHED
CVSS 7.5 HIGH
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
EPSS 5.09% · 91.7th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.09%
91.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 3.1 |
| gggeek | phpxmlrpc | 0 |
| n/a | n/a | n/a |
Timeline
- Aug 15, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 20050817 [PHPADSNEW-SA-2005-001] phpAdsNew and phpPgAds 2.0.6 fix multiple vulnerabilities mailing-list
- 16491 third-party-advisory
- DSA-840 vendor-advisory
- 16431 third-party-advisory
- 16635 third-party-advisory
- 17066 third-party-advisory
- 20050815 [DRUPAL-SA-2005-004] Drupal 4.6.3 / 4.5.5 fixes critical XML-RPC issue mailing-list
- 16693 third-party-advisory
- 16976 third-party-advisory
- 16469 third-party-advisory
- 16468 third-party-advisory
- oval:org.mitre.oval:def:9569 vdb
- 16550 third-party-advisory
- http://secunia.com/advisories/16432 technical
- http://secunia.com/advisories/16460 technical
- http://secunia.com/advisories/16619 technical
- http://secunia.com/advisories/17053 technical
- http://secunia.com/advisories/17440 technical
- http://www.debian.org/security/2005/dsa-789 mailing_list
- http://www.debian.org/security/2005/dsa-842 mailing_list
…and 14 more