LWN.net Logo

WordPress: SQL injection

Package(s):wordpress CVE #(s):
Created:March 6, 2006 Updated:March 8, 2006
Description: Patrik Karlsson reported that WordPress 1.5.2 makes use of an insufficiently filtered User Agent string in SQL queries related to comments posting. This vulnerability was already fixed in the 2.0-series of WordPress.
Alerts:
Gentoo 200603-01 2006-03-04

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds