CVE
- Id
- 13704
- CVE No.
- CVE-2005-2498
- Status
- Candidate
- Description
- Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
- Phase
- Assigned (20050808)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
100051 | 13704 | CVE-2005-2498 | BUGTRAQ:20050815 Advisory 15/2005: PHPXMLRPC Remote PHP Code Injection Vulnerability | View |
100052 | 13704 | CVE-2005-2498 | URL:http://www.securityfocus.com/archive/1/408125 | View |
100053 | 13704 | CVE-2005-2498 | MISC:http://www.hardened-php.net/advisory_152005.67.html | View |
100054 | 13704 | CVE-2005-2498 | BUGTRAQ:20050817 [PHPADSNEW-SA-2005-001] phpAdsNew and phpPgAds 2.0.6 fix multiple vulnerabilities | View |
100055 | 13704 | CVE-2005-2498 | URL:http://marc.info/?l=bugtraq&m=112431497300344&w=2 | View |
100056 | 13704 | CVE-2005-2498 | BUGTRAQ:20050815 [DRUPAL-SA-2005-004] Drupal 4.6.3 / 4.5.5 fixes critical XML-RPC issue | View |
100057 | 13704 | CVE-2005-2498 | URL:http://marc.info/?l=bugtraq&m=112412415822890&w=2 | View |
100058 | 13704 | CVE-2005-2498 | DEBIAN:DSA-789 | View |
100059 | 13704 | CVE-2005-2498 | URL:http://www.debian.org/security/2005/dsa-789 | View |
100060 | 13704 | CVE-2005-2498 | DEBIAN:DSA-798 | View |
100061 | 13704 | CVE-2005-2498 | URL:http://www.debian.org/security/2005/dsa-798 | View |
100062 | 13704 | CVE-2005-2498 | DEBIAN:DSA-840 | View |
100063 | 13704 | CVE-2005-2498 | URL:http://www.debian.org/security/2005/dsa-840 | View |
100064 | 13704 | CVE-2005-2498 | DEBIAN:DSA-842 | View |
100065 | 13704 | CVE-2005-2498 | URL:http://www.debian.org/security/2005/dsa-842 | View |
100066 | 13704 | CVE-2005-2498 | FEDORA:FLSA:166943 | View |
100067 | 13704 | CVE-2005-2498 | URL:http://www.fedoralegacy.org/updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.html | View |
100068 | 13704 | CVE-2005-2498 | GENTOO:GLSA-200509-19 | View |
100069 | 13704 | CVE-2005-2498 | URL:http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml | View |
100070 | 13704 | CVE-2005-2498 | REDHAT:RHSA-2005:748 | View |
100071 | 13704 | CVE-2005-2498 | URL:http://www.redhat.com/support/errata/RHSA-2005-748.html | View |
100072 | 13704 | CVE-2005-2498 | SUSE:SUSE-SA:2005:051 | View |
100073 | 13704 | CVE-2005-2498 | URL:http://marc.info/?l=bugtraq&m=112605112027335&w=2 | View |
100074 | 13704 | CVE-2005-2498 | SUSE:SUSE-SA:2005:049 | View |
100075 | 13704 | CVE-2005-2498 | URL:http://www.novell.com/linux/security/advisories/2005_49_php.html | View |
100076 | 13704 | CVE-2005-2498 | BID:14560 | View |
100077 | 13704 | CVE-2005-2498 | URL:http://www.securityfocus.com/bid/14560 | View |
100078 | 13704 | CVE-2005-2498 | OVAL:oval:org.mitre.oval:def:9569 | View |
100079 | 13704 | CVE-2005-2498 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9569 | View |
100080 | 13704 | CVE-2005-2498 | SECUNIA:16431 | View |
100081 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16431 | View |
100082 | 13704 | CVE-2005-2498 | SECUNIA:16432 | View |
100083 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16432 | View |
100084 | 13704 | CVE-2005-2498 | SECUNIA:16441 | View |
100085 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16441 | View |
100086 | 13704 | CVE-2005-2498 | SECUNIA:16460 | View |
100087 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16460 | View |
100088 | 13704 | CVE-2005-2498 | SECUNIA:16465 | View |
100089 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16465 | View |
100090 | 13704 | CVE-2005-2498 | SECUNIA:16468 | View |
100091 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16468 | View |
100092 | 13704 | CVE-2005-2498 | SECUNIA:16469 | View |
100093 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16469 | View |
100094 | 13704 | CVE-2005-2498 | SECUNIA:16491 | View |
100095 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16491 | View |
100096 | 13704 | CVE-2005-2498 | SECUNIA:16550 | View |
100097 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16550 | View |
100098 | 13704 | CVE-2005-2498 | SECUNIA:16558 | View |
100099 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16558 | View |
100100 | 13704 | CVE-2005-2498 | SECUNIA:16563 | View |
100101 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16563 | View |
100102 | 13704 | CVE-2005-2498 | SECUNIA:16619 | View |
100103 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16619 | View |
100104 | 13704 | CVE-2005-2498 | SECUNIA:16635 | View |
100105 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16635 | View |
100106 | 13704 | CVE-2005-2498 | SECUNIA:16693 | View |
100107 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16693 | View |
100108 | 13704 | CVE-2005-2498 | SECUNIA:16976 | View |
100109 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/16976 | View |
100110 | 13704 | CVE-2005-2498 | SECUNIA:17440 | View |
100111 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/17440 | View |
100112 | 13704 | CVE-2005-2498 | SECUNIA:17053 | View |
100113 | 13704 | CVE-2005-2498 | URL:http://secunia.com/advisories/17053 | View |
100114 | 13704 | CVE-2005-2498 | SECUNIA:17066 | View |