Search Results (Refine Search)
- CPE Product Version: cpe:/a:wordpress:wordpress:1.5.2
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2006-1263 |
Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. Published: March 18, 2006; 9:02:00 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2006-1012 |
SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment. Published: March 06, 2006; 4:02:00 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |