OSVDB ID: 18889

Title: XML-RPC for PHP (PHPXMLRPC) Nested XML Tags Arbitrary PHP Code Execution

Info

Disclosure

Aug 15, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

XML-RPC for PHP (PHPXMLRPC) contains a flaw that may allow a remote attacker to execute arbitrary PHP code. The problem is that the library does not properly sanitizing certain XML tags that are nested in a parsed PHP document before being used in an 'eval()' call, which may allow a remote attacker to execute arbitrary PHP code resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored / Private
Disclosure: OSVDB Verified
OSVDB: Web Related

Solution

Contact your vendor for an appropriate upgrade. An upgrade is required as there are no known workarounds.

Products

Gaetano Giunta

XML-RPC for PHP

1.1.1

Stig S. Bakken

PEAR XML_RPC

1.3.3

Drupal

Drupal

4.5.4
4.5.3
4.5.2
4.5.1
4.5.0

Luis Argerich

TikiWiki

1.8.5

Thorsten Rinne

phpMyFAQ

1.4.10
1.5.0 RC6

Steve Wainstead

PhpWiki

1.2.10

Wouter Demuynck

Nucleus CMS

3.2

Ralf Becker

eGroupWare

1.0.0.008-2

Joseph Engo

phpGroupWare

0.9.16.006

Akos Maroy

LiveSupport

1.0RC1

Steve Freegard

MailWatch for MailScanner

1.0.1

Matthew McNaney

phpWebSite

0.10.1

François PLANQUE

b2evolution

0.9.0

PHPAdsNew

PHPAdsNew

2.0.4

References

Credit

  • Stefan Esser - sesserBrand New Doo Doohardened-php.net - www.hardened-php.net


Direct URL: http://osvdb.org/36218