Show plain JSON{"cve": {"data_type": "CVE", "references": {"reference_data": [{"url": "http://pear.php.net/package/XML_RPC/download/1.3.1", "name": "http://pear.php.net/package/XML_RPC/download/1.3.1", "tags": ["Patch"], "refsource": "MISC"}, {"url": "http://www.gulftech.org/?node=research&article_id=00087-07012005", "name": "http://www.gulftech.org/?node=research&article_id=00087-07012005", "tags": ["Patch", "Vendor Advisory"], "refsource": "MISC"}, {"url": "http://www.hardened-php.net/advisory-022005.php", "name": "http://www.hardened-php.net/advisory-022005.php", "tags": ["Vendor Advisory"], "refsource": "MISC"}, {"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2005:109", "name": "MDKSA-2005:109", "tags": ["Patch", "Vendor Advisory"], "refsource": "MANDRAKE"}, {"url": "http://sourceforge.net/project/shownotes.php?release_id=338803", "name": "http://sourceforge.net/project/shownotes.php?release_id=338803", "tags": [], "refsource": "CONFIRM"}, {"url": "http://www.debian.org/security/2005/dsa-745", "name": "DSA-745", "tags": [], "refsource": "DEBIAN"}, {"url": "http://www.debian.org/security/2005/dsa-747", "name": "DSA-747", "tags": [], "refsource": "DEBIAN"}, {"url": "http://security.gentoo.org/glsa/glsa-200507-01.xml", "name": "GLSA-200507-01", "tags": [], "refsource": "GENTOO"}, {"url": "http://security.gentoo.org/glsa/glsa-200507-06.xml", "name": "GLSA-200507-06", "tags": [], "refsource": "GENTOO"}, {"url": "http://security.gentoo.org/glsa/glsa-200507-07.xml", "name": "GLSA-200507-07", "tags": [], "refsource": "GENTOO"}, {"url": "http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt", "name": "http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt", "tags": [], "refsource": "CONFIRM"}, {"url": "http://sourceforge.net/project/showfiles.php?group_id=87163", "name": "http://sourceforge.net/project/showfiles.php?group_id=87163", "tags": [], "refsource": "CONFIRM"}, {"url": "http://www.ampache.org/announce/3_3_1_2.php", "name": "http://www.ampache.org/announce/3_3_1_2.php", "tags": [], "refsource": "CONFIRM"}, {"url": "http://secunia.com/advisories/15852", "name": "15852", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15872", "name": "15872", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15944", "name": "15944", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15947", "name": "15947", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15957", "name": "15957", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/16001", "name": "16001", "tags": [], "refsource": "SECUNIA"}, {"url": "http://www.debian.org/security/2005/dsa-789", "name": "DSA-789", "tags": [], "refsource": "DEBIAN"}, {"url": "http://www.securityfocus.com/bid/14088", "name": "14088", "tags": [], "refsource": "BID"}, {"url": "http://securitytracker.com/id?1015336", "name": "1015336", "tags": [], "refsource": "SECTRACK"}, {"url": "http://secunia.com/advisories/18003", "name": "18003", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15810", "name": "15810", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15855", "name": "15855", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15861", "name": "15861", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15883", "name": "15883", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15884", "name": "15884", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15895", "name": "15895", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15903", "name": "15903", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15904", "name": "15904", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15916", "name": "15916", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15917", "name": "15917", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/15922", "name": "15922", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/16339", "name": "16339", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/16693", "name": "16693", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/17440", "name": "17440", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/17674", "name": "17674", "tags": [], "refsource": "SECUNIA"}, {"url": "http://www.debian.org/security/2005/dsa-746", "name": "DSA-746", "tags": [], "refsource": "DEBIAN"}, {"url": "http://www.redhat.com/support/errata/RHSA-2005-564.html", "name": "RHSA-2005:564", "tags": [], "refsource": "REDHAT"}, {"url": "http://www.novell.com/linux/security/advisories/2005_41_php_pear.html", "name": "SUSE-SA:2005:041", "tags": [], "refsource": "SUSE"}, {"url": "http://www.novell.com/linux/security/advisories/2005_49_php.html", "name": "SUSE-SA:2005:049", "tags": [], "refsource": "SUSE"}, {"url": "http://www.novell.com/linux/security/advisories/2005_18_sr.html", "name": "SUSE-SR:2005:018", "tags": [], "refsource": "SUSE"}, {"url": "http://www.vupen.com/english/advisories/2005/2827", "name": "ADV-2005-2827", "tags": [], "refsource": "VUPEN"}, {"url": "http://marc.info/?l=bugtraq&m=112008638320145&w=2", "name": "20050629 Advisory 02/2005: Remote code execution in Serendipity", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://marc.info/?l=bugtraq&m=112015336720867&w=2", "name": "20050629 [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://marc.info/?l=bugtraq&m=112605112027335&w=2", "name": "SUSE-SA:2005:051", "tags": [], "refsource": "SUSE"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A350", "name": "oval:org.mitre.oval:def:350", "tags": [], "refsource": "OVAL"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11294", "name": "oval:org.mitre.oval:def:11294", "tags": [], "refsource": "OVAL"}, {"url": "http://www.securityfocus.com/archive/1/419064/100/0/threaded", "name": "SSRT051069", "tags": [], "refsource": "HP"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "en", "value": "Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "en", "value": "NVD-CWE-Other"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2005-1921", "ASSIGNER": "secalert@redhat.com"}}, "impact": {"baseMetricV2": {"cvssV2": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "severity": "HIGH", "impactScore": 6.4, "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}}, "publishedDate": "2005-07-05T04:00Z", "configurations": {"nodes": [{"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.1.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.0rc7:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.1:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.0.2:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.0rc3:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.0rc4:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.3.0rc3:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.0rc1:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.0rc2:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.2:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.0.4:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.3.0rc1:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.3.0rc2:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.0rc6:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.2.0rc5:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:pear:xml_rpc:1.0.3:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}]}], "CVE_data_version": "4.0"}, "lastModifiedDate": "2018-10-19T15:32Z"}