Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2005-2498

Опубликовано: 15 авг. 2005
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.

РелизСтатусПримечание
dapper

released

4.5.8-1
devel

DNE

edgy

released

4.5.8-1
feisty

ignored

end of life, was needed
gutsy

DNE

hardy

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

1.0.0.009.dfsg-3-4
devel

released

1.0.0.009.dfsg-3-4
edgy

released

1.0.0.009.dfsg-3-4
feisty

released

1.0.0.009.dfsg-3-4
gutsy

released

1.0.0.009.dfsg-3-4
hardy

released

1.0.0.009.dfsg-3-4
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

DNE

edgy

not-affected

feisty

DNE

gutsy

DNE

hardy

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

5.1.2-1ubuntu3.9
devel

released

5.2.3-1ubuntu5
edgy

released

5.1.6-1ubuntu2.6
feisty

released

5.2.1-0ubuntu1.4
gutsy

released

5.2.3-1ubuntu5
hardy

released

5.2.3-1ubuntu5
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

0.9.16.010-1
devel

released

0.9.16.010-1
edgy

released

0.9.16.010-1
feisty

released

0.9.16.010-1
gutsy

released

0.9.16.010-1
hardy

released

0.9.16.010-1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 89%
0.04688
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
около 20 лет назад

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.

nvd
около 20 лет назад

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.

debian
около 20 лет назад

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML- ...

github
больше 3 лет назад

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.

EPSS

Процентиль: 89%
0.04688
Низкий

7.5 High

CVSS2