CVE
- Id
- 13127
- CVE No.
- CVE-2005-1921
- Status
- Candidate
- Description
- Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
- Phase
- Assigned (20050608)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
94483 | 13127 | CVE-2005-1921 | BUGTRAQ:20050629 Advisory 02/2005: Remote code execution in Serendipity | View |
94484 | 13127 | CVE-2005-1921 | URL:http://marc.info/?l=bugtraq&m=112008638320145&w=2 | View |
94485 | 13127 | CVE-2005-1921 | MISC:http://pear.php.net/package/XML_RPC/download/1.3.1 | View |
94486 | 13127 | CVE-2005-1921 | MISC:http://www.gulftech.org/?node=research&article_id=00087-07012005 | View |
94487 | 13127 | CVE-2005-1921 | MISC:http://www.hardened-php.net/advisory-022005.php | View |
94488 | 13127 | CVE-2005-1921 | CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=338803 | View |
94489 | 13127 | CVE-2005-1921 | DEBIAN:DSA-745 | View |
94490 | 13127 | CVE-2005-1921 | URL:http://www.debian.org/security/2005/dsa-745 | View |
94491 | 13127 | CVE-2005-1921 | DEBIAN:DSA-747 | View |
94492 | 13127 | CVE-2005-1921 | URL:http://www.debian.org/security/2005/dsa-747 | View |
94493 | 13127 | CVE-2005-1921 | DEBIAN:DSA-789 | View |
94494 | 13127 | CVE-2005-1921 | URL:http://www.debian.org/security/2005/dsa-789 | View |
94495 | 13127 | CVE-2005-1921 | DEBIAN:DSA-746 | View |
94496 | 13127 | CVE-2005-1921 | URL:http://www.debian.org/security/2005/dsa-746 | View |
94497 | 13127 | CVE-2005-1921 | GENTOO:GLSA-200507-01 | View |
94498 | 13127 | CVE-2005-1921 | URL:http://security.gentoo.org/glsa/glsa-200507-01.xml | View |
94499 | 13127 | CVE-2005-1921 | GENTOO:GLSA-200507-06 | View |
94500 | 13127 | CVE-2005-1921 | URL:http://security.gentoo.org/glsa/glsa-200507-06.xml | View |
94501 | 13127 | CVE-2005-1921 | GENTOO:GLSA-200507-07 | View |
94502 | 13127 | CVE-2005-1921 | URL:http://security.gentoo.org/glsa/glsa-200507-07.xml | View |
94503 | 13127 | CVE-2005-1921 | HP:HPSBTU02083 | View |
94504 | 13127 | CVE-2005-1921 | URL:http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded | View |
94505 | 13127 | CVE-2005-1921 | HP:SSRT051069 | View |
94506 | 13127 | CVE-2005-1921 | URL:http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded | View |
94507 | 13127 | CVE-2005-1921 | MANDRAKE:MDKSA-2005:109 | View |
94508 | 13127 | CVE-2005-1921 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:109 | View |
94509 | 13127 | CVE-2005-1921 | REDHAT:RHSA-2005:564 | View |
94510 | 13127 | CVE-2005-1921 | URL:http://www.redhat.com/support/errata/RHSA-2005-564.html | View |
94511 | 13127 | CVE-2005-1921 | SUSE:SUSE-SA:2005:051 | View |
94512 | 13127 | CVE-2005-1921 | URL:http://marc.info/?l=bugtraq&m=112605112027335&w=2 | View |
94513 | 13127 | CVE-2005-1921 | BUGTRAQ:20050629 [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue | View |
94514 | 13127 | CVE-2005-1921 | URL:http://marc.info/?l=bugtraq&m=112015336720867&w=2 | View |
94515 | 13127 | CVE-2005-1921 | CONFIRM:http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt | View |
94516 | 13127 | CVE-2005-1921 | CONFIRM:http://sourceforge.net/project/showfiles.php?group_id=87163 | View |
94517 | 13127 | CVE-2005-1921 | CONFIRM:http://www.ampache.org/announce/3_3_1_2.php | View |
94518 | 13127 | CVE-2005-1921 | SUSE:SUSE-SA:2005:041 | View |
94519 | 13127 | CVE-2005-1921 | URL:http://www.novell.com/linux/security/advisories/2005_41_php_pear.html | View |
94520 | 13127 | CVE-2005-1921 | SUSE:SUSE-SA:2005:049 | View |
94521 | 13127 | CVE-2005-1921 | URL:http://www.novell.com/linux/security/advisories/2005_49_php.html | View |
94522 | 13127 | CVE-2005-1921 | SUSE:SUSE-SR:2005:018 | View |
94523 | 13127 | CVE-2005-1921 | URL:http://www.novell.com/linux/security/advisories/2005_18_sr.html | View |
94524 | 13127 | CVE-2005-1921 | BID:14088 | View |
94525 | 13127 | CVE-2005-1921 | URL:http://www.securityfocus.com/bid/14088 | View |
94526 | 13127 | CVE-2005-1921 | OVAL:oval:org.mitre.oval:def:11294 | View |
94527 | 13127 | CVE-2005-1921 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11294 | View |
94528 | 13127 | CVE-2005-1921 | VUPEN:ADV-2005-2827 | View |
94529 | 13127 | CVE-2005-1921 | URL:http://www.vupen.com/english/advisories/2005/2827 | View |
94530 | 13127 | CVE-2005-1921 | OVAL:oval:org.mitre.oval:def:350 | View |
94531 | 13127 | CVE-2005-1921 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:350 | View |
94532 | 13127 | CVE-2005-1921 | SECTRACK:1015336 | View |
94533 | 13127 | CVE-2005-1921 | URL:http://securitytracker.com/id?1015336 | View |
94534 | 13127 | CVE-2005-1921 | SECUNIA:15852 | View |
94535 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15852 | View |
94536 | 13127 | CVE-2005-1921 | SECUNIA:15872 | View |
94537 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15872 | View |
94538 | 13127 | CVE-2005-1921 | SECUNIA:15944 | View |
94539 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15944 | View |
94540 | 13127 | CVE-2005-1921 | SECUNIA:15947 | View |
94541 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15947 | View |
94542 | 13127 | CVE-2005-1921 | SECUNIA:15957 | View |
94543 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15957 | View |
94544 | 13127 | CVE-2005-1921 | SECUNIA:16001 | View |
94545 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/16001 | View |
94546 | 13127 | CVE-2005-1921 | SECUNIA:18003 | View |
94547 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/18003 | View |
94548 | 13127 | CVE-2005-1921 | SECUNIA:15810 | View |
94549 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15810 | View |
94550 | 13127 | CVE-2005-1921 | SECUNIA:15855 | View |
94551 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15855 | View |
94552 | 13127 | CVE-2005-1921 | SECUNIA:15861 | View |
94553 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15861 | View |
94554 | 13127 | CVE-2005-1921 | SECUNIA:15883 | View |
94555 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15883 | View |
94556 | 13127 | CVE-2005-1921 | SECUNIA:15884 | View |
94557 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15884 | View |
94558 | 13127 | CVE-2005-1921 | SECUNIA:15895 | View |
94559 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15895 | View |
94560 | 13127 | CVE-2005-1921 | SECUNIA:15903 | View |
94561 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15903 | View |
94562 | 13127 | CVE-2005-1921 | SECUNIA:15904 | View |
94563 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15904 | View |
94564 | 13127 | CVE-2005-1921 | SECUNIA:15916 | View |
94565 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15916 | View |
94566 | 13127 | CVE-2005-1921 | SECUNIA:15917 | View |
94567 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15917 | View |
94568 | 13127 | CVE-2005-1921 | SECUNIA:15922 | View |
94569 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/15922 | View |
94570 | 13127 | CVE-2005-1921 | SECUNIA:16339 | View |
94571 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/16339 | View |
94572 | 13127 | CVE-2005-1921 | SECUNIA:16693 | View |
94573 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/16693 | View |
94574 | 13127 | CVE-2005-1921 | SECUNIA:17440 | View |
94575 | 13127 | CVE-2005-1921 | URL:http://secunia.com/advisories/17440 | View |
94576 | 13127 | CVE-2005-1921 | SECUNIA:17674 | View |