Back
CVE-2005-1921
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
Published: Jul 5, 2005
Modified: Jun 16, 2026
CWE-94
CVSS Metrics
Affected Products (6)
| Vendor | Product | Version |
|---|---|---|
| php | xml_rpc | * |
| gggeek | phpxmlrpc | * |
| drupal | drupal | * < 4.5.4 |
| drupal | drupal | * ≥ 4.6.0 < 4.6.2 |
| tiki | tikiwiki_cms\/groupware | * < 1.8.5 |
| debian | debian_linux | 3.1 |
GitHub Security Advisory GHSA-7mjj-9265-43wm
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and...
References (100)
- http://marc.info/?l=bugtraq&m=112008638320145&w=2 Third Party Advisory
- http://marc.info/?l=bugtraq&m=112015336720867&w=2 Third Party Advisory
- http://marc.info/?l=bugtraq&m=112605112027335&w=2 Third Party Advisory
- http://pear.php.net/package/XML_RPC/download/1.3.1 Patch, Product
- http://secunia.com/advisories/15810 Broken Link
- http://secunia.com/advisories/15852 Broken Link
- http://secunia.com/advisories/15855 Broken Link
- http://secunia.com/advisories/15861 Broken Link
- http://secunia.com/advisories/15872 Broken Link
- http://secunia.com/advisories/15883 Broken Link
- http://secunia.com/advisories/15884 Broken Link
- http://secunia.com/advisories/15895 Broken Link
- http://secunia.com/advisories/15903 Broken Link
- http://secunia.com/advisories/15904 Broken Link
- http://secunia.com/advisories/15916 Broken Link
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
79.07%
Top 0% most likely to be exploited
Threat Score
63.7 / 100
Data Sources
NVD
EPSS
GitHub