CVE-2006-1012
Publication date 6 March 2006
Last updated 17 July 2025
Ubuntu priority
Description
SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.