Title: XML-RPC for PHP (PHPXMLRPC) Nested XML Tags Arbitrary PHP Code Execution
Info
Disclosure
Aug 15, 2005
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
XML-RPC for PHP (PHPXMLRPC) contains a flaw that may allow a remote attacker to execute arbitrary PHP code. The problem is that the library does not properly sanitizing certain XML tags that are nested in a parsed PHP document before being used in an 'eval()' call, which may allow a remote attacker to execute arbitrary PHP code resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Contact your vendor for an appropriate upgrade. An upgrade is required as there are no known workarounds.