Back

CVE-2006-1032

Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.

Published: Mar 7, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
phprpc phprpc 0.7
phprpc phprpc 0.8
phprpc phprpc 0.9

GitHub Security Advisory GHSA-7x6m-57gq-rcf3

Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.57%

Top 12% most likely to be exploited

Threat Score 31.1 / 100

Data Sources

NVD EPSS GitHub