CVE-2005-2498
Summary
| CVE | CVE-2005-2498 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-08-15 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 3.1 | All | All | All |
| Application | Gggeek | Phpxmlrpc | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHPXMLRPC and PEAR XML_RPC Remote Code Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Secunia - Advisories - Drupal XML-RPC PHP Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - MAXdev MD-Pro Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - phpGroupWare Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| '[PHPADSNEW-SA-2005-001] phpAdsNew and phpPgAds 2.0.6 fix multiple' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Secunia - Advisories - Nucleus CMS XML-RPC Nested XML Tags PHP Code Execution | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - MailWatch for MailScanner XML-RPC PHP Code Execution | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - Gentoo update for PEAR-XML_RPC / phpxmlrpc | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - b2evolution XML-RPC PHP Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Debian -- Security Information -- DSA-798-1 phpgroupware | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List, Third Party Advisory |
| Secunia - Advisories - XML-RPC for PHP Nested XML Tags PHP Code Execution | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Hardened-PHP Project - PHP Security - Advisory 15/2005 | af854a3a-2127-422b-91ae-364da2661108 | www.hardened-php.net | Not Applicable, Patch, Vendor Advisory |
| Secunia - Advisories - phpAdsNew Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-842-1 egroupware | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List, Third Party Advisory |
| Secunia - Advisories - Gentoo update for php | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - Debian update for drupal | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - eGroupWare XML-RPC Nested XML Tags PHP Code Execution | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - Slackware update for php | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| 'SUSE Security Announcement: php4, php5 remote code execution' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Secunia - Advisories - phpMyFAQ XML-RPC Nested XML Tags PHP Code Execution | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| Secunia - Advisories - Debian update for egroupware | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Secunia - Advisories - TikiWiki XML-RPC Nested XML Tags PHP Code Execution | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Debian -- Security Information -- DSA-840-1 drupal | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List |
| Gentoo Linux Documentation -- PHP: Vulnerabilities in included PCRE and XML-RPC libraries | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Third Party Advisory |
| '[DRUPAL-SA-2005-004] Drupal 4.6.3 / 4.5.5 fixes critical XML-RPC issue' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | Broken Link |
| Secunia - Advisories - SUSE update for php4/php5 | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| Secunia - Advisories - phpPgAds Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| The Fedora Legacy Project | af854a3a-2127-422b-91ae-364da2661108 | www.fedoralegacy.org | Broken Link |
| Debian -- Security Information -- DSA-789-1 php4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.