>> Drupal XML-RPC for PHP Nested Tags Remote Code Execution
Title : Drupal XML-RPC for PHP Nested Tags Remote Code Execution VUPEN ID : VUPEN/ADV-2005-1415 CVE ID : CVE-2005-2498 CWE ID : CWE-
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-08-15
Technical Description
A vulnerability was identified in Drupal, which could be exploited by remote attackers to execute arbitrary code. This flaw is due to an input validation error in the XML-RPC library when processing, via an "eval()" call, certain XML tags nested in parsed documents, which could be exploited by remote attackers to execute arbitrary PHP commands. For additional information, see : VUPEN/ADV-2005-1413
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.