WordPress security changelog
HIGH CVE-2006-1012 Modified

WordPress 1.5.2, and possibly other versions before 2.0,: SQL injection

WordPress 1.5.2, and possibly other versions before 2.0, is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

CVE / CNA score 7.5 CVSS · cve@mitre.org
NVD score 7.5 CVSS 2.0 · nvd@nist.gov
Component
WordPress 1.5.2, and possibly other versions before 2.0,
Plugin slug
Core
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Mar 06, 2006
Weakness
NVD-CWE-Other

This CVE was published Mar 06, 2006 and is one of 45 known issues for WordPress core.

Patch or disable the affected component.

Update WordPress 1.5.2, and possibly other versions before 2.0, to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.

NVD vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Primary and upstream sources