Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Edd Dumbill Subscribe
Filtered by product Phpxmlrpc
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2498 1 Edd Dumbill 1 Phpxmlrpc 2017-10-10 5.0 MEDIUM N/A
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.