Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.
Loading...
Loading...
Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.
March 7, 2006
April 16, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (2 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
phpRPC < 0.7 - Remote Code Execution
Open source ↗phpRPC Library 0.7 - XML Data Decoding Remote Code Execution (1)
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-1032
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.