CVE-2005-1921: Code Injection
Eval injection vulnerability in PEAR XMLRPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1921?
CVE-2005-1921 has a medium severity rating, indicating a moderate risk.
How do I fix CVE-2005-1921?
To fix CVE-2005-1921, upgrade PEAR XML_RPC to version 1.3.1 or later.
Which software is affected by CVE-2005-1921?
CVE-2005-1921 affects software such as WordPress, Drupal, and TikiWiki that utilize PEAR XML_RPC version 1.3.0 and earlier.
What type of vulnerability is CVE-2005-1921?
CVE-2005-1921 is classified as an eval injection vulnerability.
Is there a patch available for CVE-2005-1921?
Yes, a patch is available by upgrading to PEAR XML_RPC version 1.3.1 or above.