CVE-2006-0985: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0985?
The severity of CVE-2006-0985 is generally considered to be medium due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2006-0985?
To fix CVE-2006-0985, upgrade your WordPress installation to version 2.0.2 or later.
What versions of WordPress are affected by CVE-2006-0985?
CVE-2006-0985 affects WordPress versions 2.0.1 and earlier, along with some earlier versions down to 1.0.
What types of vulnerabilities are present in CVE-2006-0985?
CVE-2006-0985 contains multiple cross-site scripting (XSS) vulnerabilities that allow for script injection through comment inputs.
Can CVE-2006-0985 be exploited without authentication?
Yes, CVE-2006-0985 can be exploited by unauthenticated remote attackers who interact with the "post comment" functionality.