18889 : XML-RPC for PHP (PHPXMLRPC) Nested XML Tags Arbitrary PHP Code Execution
Printer | http://osvdb.org/18889 | Email This | Edit Vulnerability

Views This Week

1

Views All Time

45

Info

Last Modified

6 months ago

Percent Complete

100%

Disclosure

Aug 15, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

XML-RPC for PHP (PHPXMLRPC) contains a flaw that may allow a remote attacker to execute arbitrary PHP code. The problem is that the library does not properly sanitizing certain XML tags that are nested in a parsed PHP document before being used in an 'eval()' call, which may allow a remote attacker to execute arbitrary PHP code resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored / Private
Disclosure: OSVDB Verified
OSVDB: Web Related

Technical

The XML-RPC for PHP library, as well as the PEAR XMLRPC library, are used in a wide variety of products. Along with the products listed here, others may be vulnerable.

Solution

Contact your vendor for an appropriate upgrade. An upgrade is required as there are no known workarounds.

Products

Gaetano Giunta
Watch-list
XML-RPC for PHP
Watch-list
1.1.1
Stig S. Bakken
Watch-list
PEAR XML_RPC
Watch-list
1.3.3
Drupal
Watch-list
Drupal
Watch-list
4.5.4
4.5.3
4.5.2
4.5.1
4.5.0
Luis Argerich
Watch-list
TikiWiki
Watch-list
1.8.5
Thorsten Rinne
Watch-list
phpMyFAQ
Watch-list
1.4.10
1.5.0 RC6
Steve Wainstead
Watch-list
PhpWiki
Watch-list
1.2.10
Wouter Demuynck
Watch-list
Nucleus CMS
Watch-list
3.2
Ralf Becker
Watch-list
eGroupWare
Watch-list
1.0.0.008-2
Joseph Engo
Watch-list
phpGroupWare
Watch-list
0.9.16.006
Akos Maroy
Watch-list
LiveSupport
Watch-list
1.0RC1
Steve Freegard
Watch-list
MailWatch for MailScanner
Watch-list
1.0.1
Matthew McNaney
Watch-list
phpWebSite
Watch-list
0.10.1
François PLANQUE
Watch-list
b2evolution
Watch-list
0.9.0
PHPAdsNew
Watch-list
PHPAdsNew
Watch-list
2.0.4

References

Tools & Filters

Nessus

19491 19518 19532 19533 19534 19538 19568 19574 19667 19668 19809 19818 19846 19859 19863 19902 20578 21527

Credit

  • Stefan Esser - sesserBrand New Doo Doohardened-php.net - www.hardened-php.net

Blogs

None found at this time

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use