CVE-2005-1921

critical

Description

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A350

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11294

https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-1923

http://www.vupen.com/english/advisories/2005/2827

http://www.securityfocus.com/bid/14088

http://www.securityfocus.com/archive/1/419064/100/0/threaded

http://www.redhat.com/support/errata/RHSA-2005-564.html

http://www.novell.com/linux/security/advisories/2005_49_php.html

http://www.novell.com/linux/security/advisories/2005_41_php_pear.html

http://www.novell.com/linux/security/advisories/2005_18_sr.html

http://www.hardened-php.net/advisory-022005.php

http://www.gulftech.org/?node=research&article_id=00087-07012005

http://www.ampache.org/announce/3_3_1_2.php

http://sourceforge.net/project/shownotes.php?release_id=338803

http://sourceforge.net/project/showfiles.php?group_id=87163

http://securitytracker.com/id?1015336

http://secunia.com/advisories/18003

http://secunia.com/advisories/17674

http://secunia.com/advisories/17440

http://secunia.com/advisories/16693

http://secunia.com/advisories/16339

http://secunia.com/advisories/16001

http://secunia.com/advisories/15957

http://secunia.com/advisories/15947

http://secunia.com/advisories/15944

http://secunia.com/advisories/15922

http://secunia.com/advisories/15917

http://secunia.com/advisories/15916

http://secunia.com/advisories/15904

http://secunia.com/advisories/15903

http://secunia.com/advisories/15895

http://secunia.com/advisories/15884

http://secunia.com/advisories/15883

http://secunia.com/advisories/15872

http://secunia.com/advisories/15861

http://secunia.com/advisories/15855

http://secunia.com/advisories/15852

http://secunia.com/advisories/15810

http://pear.php.net/package/XML_RPC/download/1.3.1

Details

Source: Mitre, NVD

Published: 2005-07-05

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.79071