Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
References
Link Providers
http://marc.info/?l=bugtraq&m=112008638320145&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=112015336720867&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=112605112027335&w=2 cve-icon cve-icon
http://pear.php.net/package/XML_RPC/download/1.3.1 cve-icon cve-icon
http://secunia.com/advisories/15810 cve-icon cve-icon
http://secunia.com/advisories/15852 cve-icon cve-icon
http://secunia.com/advisories/15855 cve-icon cve-icon
http://secunia.com/advisories/15861 cve-icon cve-icon
http://secunia.com/advisories/15872 cve-icon cve-icon
http://secunia.com/advisories/15883 cve-icon cve-icon
http://secunia.com/advisories/15884 cve-icon cve-icon
http://secunia.com/advisories/15895 cve-icon cve-icon
http://secunia.com/advisories/15903 cve-icon cve-icon
http://secunia.com/advisories/15904 cve-icon cve-icon
http://secunia.com/advisories/15916 cve-icon cve-icon
http://secunia.com/advisories/15917 cve-icon cve-icon
http://secunia.com/advisories/15922 cve-icon cve-icon
http://secunia.com/advisories/15944 cve-icon cve-icon
http://secunia.com/advisories/15947 cve-icon cve-icon
http://secunia.com/advisories/15957 cve-icon cve-icon
http://secunia.com/advisories/16001 cve-icon cve-icon
http://secunia.com/advisories/16339 cve-icon cve-icon
http://secunia.com/advisories/16693 cve-icon cve-icon
http://secunia.com/advisories/17440 cve-icon cve-icon
http://secunia.com/advisories/17674 cve-icon cve-icon
http://secunia.com/advisories/18003 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200507-01.xml cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200507-06.xml cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200507-07.xml cve-icon cve-icon
http://securitytracker.com/id?1015336 cve-icon cve-icon
http://sourceforge.net/project/showfiles.php?group_id=87163 cve-icon cve-icon
http://sourceforge.net/project/shownotes.php?release_id=338803 cve-icon cve-icon
http://www.ampache.org/announce/3_3_1_2.php cve-icon cve-icon
http://www.debian.org/security/2005/dsa-745 cve-icon cve-icon
http://www.debian.org/security/2005/dsa-746 cve-icon cve-icon
http://www.debian.org/security/2005/dsa-747 cve-icon cve-icon
http://www.debian.org/security/2005/dsa-789 cve-icon cve-icon
http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt cve-icon cve-icon
http://www.gulftech.org/?node=research&article_id=00087-07012005 cve-icon cve-icon
http://www.hardened-php.net/advisory-022005.php cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2005:109 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2005_18_sr.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2005_41_php_pear.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2005_49_php.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2005-564.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/419064/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/14088 cve-icon cve-icon
http://www.vupen.com/english/advisories/2005/2827 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2005-1921 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11294 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A350 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2005-1921 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2005-07-01T04:00:00

Updated: 2024-08-07T22:06:57.671Z

Reserved: 2005-06-08T00:00:00

Link: CVE-2005-1921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-07-05T04:00:00.000

Modified: 2024-11-20T23:58:25.340

Link: CVE-2005-1921

cve-icon Redhat

Severity : Important

Publid Date: 2005-06-29T00:00:00Z

Links: CVE-2005-1921 - Bugzilla