peter bassill · operator
$ cve CVE-2006-1032 JSON

CVE-2006-1032 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.6% (pctl 89)

Patch early

A public exploit exists.

Description

Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.57% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploityes
Published2006-03-07
Last modified2026-06-16

Affected (1)

VendorProduct
phprpcphprpc

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD