Back
CVE-2005-2498
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.
Published: Aug 15, 2005
Modified: Jun 16, 2026
CWE-94
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| gggeek | phpxmlrpc | * |
| debian | debian_linux | 3.1 |
GitHub Security Advisory GHSA-mcp5-3g3r-5wm5
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in...
References (66)
- http://marc.info/?l=bugtraq&m=112412415822890&w=2 Third Party Advisory
- http://marc.info/?l=bugtraq&m=112431497300344&w=2 Third Party Advisory
- http://marc.info/?l=bugtraq&m=112605112027335&w=2 Third Party Advisory
- http://secunia.com/advisories/16431 Broken Link
- http://secunia.com/advisories/16432 Broken Link
- http://secunia.com/advisories/16441 Broken Link
- http://secunia.com/advisories/16460 Broken Link
- http://secunia.com/advisories/16465 Broken Link
- http://secunia.com/advisories/16468 Broken Link
- http://secunia.com/advisories/16469 Broken Link
- http://secunia.com/advisories/16491 Broken Link
- http://secunia.com/advisories/16550 Broken Link
- http://secunia.com/advisories/16558 Broken Link
- http://secunia.com/advisories/16563 Broken Link
- http://secunia.com/advisories/16619 Broken Link
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
5.09%
Top 8% most likely to be exploited
Threat Score
31.5 / 100
Data Sources
NVD
EPSS
GitHub