Unrated severityNVD Advisory· Published Mar 6, 2006· Updated Jun 16, 2026
CVE-2006-1012
CVE-2006-1012
Description
SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
- (no CPE)range: <=1.5.2
Patches
Vulnerability mechanics
References
5- secunia.com/advisories/19109nvdPatchVendor Advisory
- www.gentoo.org/security/en/glsa/glsa-200603-01.xmlnvdPatchVendor Advisory
- secunia.com/advisories/19123nvd
- www.securityfocus.com/bid/16950nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/25321nvd
News mentions
0No linked articles in our index yet.