Back to search

CVE-2005-2108

HIGH
7.5NVD

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

CVSS v2.0 Score

7.5
/ 10.0
HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P

Information

Published
5 juil. 2005
Updated
16 avr. 2026
Status
Modified
Source
cve@mitre.org

Affected products

wordpress wordpressAll WordPress CVEs →
Versions : 1.0, 1.0.1, 1.0.2, 1.2, 1.5

Weaknesses (CWE)

NVD-CWE-Other

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring