Description
WordPress is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process; this may result in total compromise of the web server. WordPress versions prior to 1.5.2 are vulnerable.
Remediation
Update to WordPress version 1.5.2 or latest
References
http://www.securityfocus.com/bid/14533/exploit
http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0234.html
Related Vulnerabilities
WordPress Plugin Comment Rating Cross-Site Request Forgery (2.9.20)
WordPress Plugin Zingiri Web Shop Multiple Cross-Site Scripting Vulnerabilities (2.4.1)
WordPress Plugin WordPress fancyBox Lightbox Cross-Site Scripting (1.0.1)
Elgg Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-3964)
WordPress Plugin Simple Fields Cross-Site Scripting (1.4.11)