CVE-2005-2498
published 2005-08-15CVE-2005-2498: Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3)…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.09%
91.5th percentile
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| gggeek | phpxmlrpc | <= 1.1.1 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mcp5-3g3r-5wm5: Eval injection vulnerability in PHPXMLRPC 1
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2005-2498 [HIGH] CWE-94 GHSA-mcp5-3g3r-5wm5: Eval injection vulnerability in PHPXMLRPC 1
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
Ubuntu
PHP4 vulnerabilities
vendor_ubuntu·2005-08-21
CVE-2005-1759 PHP4 vulnerabilities
Title: PHP4 vulnerabilities
Summary: PHP4 vulnerabilities
CAN-2005-1751:
The php4-dev package ships a copy of the "shtool" utility in
/usr/lib/php4/build/, which provides useful functionality for
developers of software packages. Eric Romang discovered that shtool
created temporary files in an insecure manner. This could allow
a symlink attack to create or overwrite arbitrary files with the
privileges of the user invoking the shtool program.
CAN-1005-1759:
The creation of temporary files in shtool was also vulnerable to a
race condition which allowed a local user to read the contents of the
temporary file. However, this file does not usually contain sensitive
information since shtool is usually used for building software
packages.
CAN-2005-2498:
Stefan Esser discovered another remote
Red Hat
security flaw
vendor_redhat·2005-08-14·CVSS 7.5
CVE-2005-2498 [HIGH] security flaw
security flaw
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
No detection rules found.
CWE
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
mitre_cwe
CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
Modes of Introduction:
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Implementation
Note: This weakness is prevalent in handler/dispatch procedures that might want to invoke a large number of functions, or set a large number of variables.
Common Consequences:
Scope: Confidentiality. Impact: Read Files or Directories, Read Application Data. The injected code could access restricted data / files.
Scope: Access Control. Impact:
CWE
Improper Control of Generation of Code ('Code Injection')
mitre_cwe
CWE-94 Improper Control of Generation of Code ('Code Injection')
CWE-94: Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Modes of Introduction:
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Common Consequences:
Scope: Access Control. Impact: Bypass Protection Mechanism. In some cases, injectable code controls authentication; this may lead to a remote vulnerability.
Scope: Access Control. Impact: Gain Privileges or Assume Identity. Injected code can access resources that the attacker is directly prevented from ac
http://marc.info/?l=bugtraq&m=112412415822890&w=2http://marc.info/?l=bugtraq&m=112431497300344&w=2http://marc.info/?l=bugtraq&m=112605112027335&w=2http://secunia.com/advisories/16431http://secunia.com/advisories/16432http://secunia.com/advisories/16441http://secunia.com/advisories/16460http://secunia.com/advisories/16465http://secunia.com/advisories/16468http://secunia.com/advisories/16469http://secunia.com/advisories/16491http://secunia.com/advisories/16550http://secunia.com/advisories/16558http://secunia.com/advisories/16563http://secunia.com/advisories/16619http://secunia.com/advisories/16635http://secunia.com/advisories/16693http://secunia.com/advisories/16976http://secunia.com/advisories/17053http://secunia.com/advisories/17066http://secunia.com/advisories/17440http://www.debian.org/security/2005/dsa-789http://www.debian.org/security/2005/dsa-798http://www.debian.org/security/2005/dsa-840http://www.debian.org/security/2005/dsa-842http://www.fedoralegacy.org/updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200509-19.xmlhttp://www.hardened-php.net/advisory_152005.67.htmlhttp://www.novell.com/linux/security/advisories/2005_49_php.htmlhttp://www.redhat.com/support/errata/RHSA-2005-748.htmlhttp://www.securityfocus.com/archive/1/408125http://www.securityfocus.com/bid/14560https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9569http://marc.info/?l=bugtraq&m=112412415822890&w=2http://marc.info/?l=bugtraq&m=112431497300344&w=2http://marc.info/?l=bugtraq&m=112605112027335&w=2http://secunia.com/advisories/16431http://secunia.com/advisories/16432http://secunia.com/advisories/16441http://secunia.com/advisories/16460http://secunia.com/advisories/16465http://secunia.com/advisories/16468http://secunia.com/advisories/16469http://secunia.com/advisories/16491http://secunia.com/advisories/16550http://secunia.com/advisories/16558http://secunia.com/advisories/16563http://secunia.com/advisories/16619http://secunia.com/advisories/16635http://secunia.com/advisories/16693http://secunia.com/advisories/16976http://secunia.com/advisories/17053http://secunia.com/advisories/17066http://secunia.com/advisories/17440http://www.debian.org/security/2005/dsa-789http://www.debian.org/security/2005/dsa-798http://www.debian.org/security/2005/dsa-840http://www.debian.org/security/2005/dsa-842http://www.fedoralegacy.org/updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200509-19.xmlhttp://www.hardened-php.net/advisory_152005.67.htmlhttp://www.novell.com/linux/security/advisories/2005_49_php.htmlhttp://www.redhat.com/support/errata/RHSA-2005-748.htmlhttp://www.securityfocus.com/archive/1/408125http://www.securityfocus.com/bid/14560https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9569
2005-08-15
Published