Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2005-2498

21
FAUCET Score

CVE-2005-2498 describes an eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier, impacting products like Drupal, phpAdsNew, and phpgroupware. This flaw allows remote attackers to execute arbitrary PHP code by injecting specially crafted, nested XML tags into an eval function call. With a CVSS score of 7.5, this vulnerability is considered highly severe, enabling full compromise of confidentiality, integrity, and availability with low attack complexity and no authentication required. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.1.1CPE matchmatch criteria
cpe:2.3:a:gggeek:phpxmlrpc:*:*:*:*:*:*:*:*
3.1CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.09%
Probability of exploitation in next 30 days
EPSS Percentile
91.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0509 is in the 85th percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: php-0:4.3.2-25.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: php-0:4.3.9-3.8
View patch

Vendor Advisories (1)

redhatCVE-2005-2498Important

security flaw

Aug 14, 2005

References

marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
secunia.com / advisories/16431
Broken Link
secunia.com / advisories/16432
Broken Link
secunia.com / advisories/16441
Broken Link
secunia.com / advisories/16460
Broken Link
secunia.com / advisories/16465
Broken Link
secunia.com / advisories/16468
Broken Link
secunia.com / advisories/16469
Broken Link
secunia.com / advisories/16491
Broken Link
secunia.com / advisories/16550
Broken Link
secunia.com / advisories/16558
Broken Link
secunia.com / advisories/16563
Broken Link
secunia.com / advisories/16619
Broken Link
secunia.com / advisories/16635
Broken Link
secunia.com / advisories/16693
Broken Link
secunia.com / advisories/16976
Broken Link
secunia.com / advisories/17053
Broken Link
secunia.com / advisories/17066
Broken Link
secunia.com / advisories/17440
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9569
Broken Link
debian.org / security/2005/dsa-789
Mailing ListThird Party Advisory
debian.org / security/2005/dsa-798
Mailing ListThird Party Advisory
debian.org / security/2005/dsa-840
Mailing List
debian.org / security/2005/dsa-842
Mailing ListThird Party Advisory
fedoralegacy.org / updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.html
Broken Link
gentoo.org / security/en/glsa/glsa-200509-19.xml
Third Party Advisory
hardened-php.net / advisory_152005.67.html
Not ApplicablePatchVendor Advisory
novell.com / linux/security/advisories/2005_49_php.html
Broken Link
redhat.com / support/errata/RHSA-2005-748.html
Broken Link
securityfocus.com / archive/1/408125
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/14560
Broken LinkThird Party AdvisoryVDB Entry