CVE-2005-2612: Code Injection
Published Aug 17, 2005
·Updated
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cachelastpostdate[server] cookie.
Affected Software
8 affected components
WordPress=1.0
WordPress=1.0.1
WordPress=1.0.2
WordPress=1.2
WordPress=1.5
WordPress=1.5.1
WordPress=1.5.1.2
WordPress=1.5.1.3
Event History
Aug 17, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2612?
CVE-2005-2612 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2005-2612?
To fix CVE-2005-2612, upgrade to the latest version of WordPress that is not affected by this vulnerability.
3
Which versions of WordPress are affected by CVE-2005-2612?
CVE-2005-2612 affects WordPress versions 1.5.1.3 and earlier.
4
Can CVE-2005-2612 be exploited remotely?
Yes, CVE-2005-2612 can be exploited remotely by attackers using specially crafted cookies.
5
What type of vulnerability is CVE-2005-2612?
CVE-2005-2612 is a direct code injection vulnerability.