CVE Vulnerabilities

CVE-2005-2108

Published: Jul 05, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress1.0 (including)1.0 (including)
WordpressWordpress1.0.1 (including)1.0.1 (including)
WordpressWordpress1.0.2 (including)1.0.2 (including)
WordpressWordpress1.2 (including)1.2 (including)
WordpressWordpress1.5 (including)1.5 (including)
WordpressWordpress1.5.1 (including)1.5.1 (including)
WordpressWordpress1.5.1.2 (including)1.5.1.2 (including)

References