CVE-2005-2108

Wordpress - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by GulfTech Security · perlwebappsphp
https://www.exploit-db.com/exploits/1077

Scores

EPSS 0.0106
EPSS Percentile 77.7%

Details

Status published
Products (7)
wordpress/wordpress 1.0
wordpress/wordpress 1.0.1
wordpress/wordpress 1.0.2
wordpress/wordpress 1.2
wordpress/wordpress 1.5
wordpress/wordpress 1.5.1
wordpress/wordpress 1.5.1.2
Published Jul 05, 2005
Tracked Since Feb 18, 2026