Description
SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin BIC Media Widget Cross-Site Scripting (1.0)
WordPress Plugin Popular Posts by BestWebSoft Cross-Site Scripting (1.0.4)
FluxBB Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2020-28873)
Jenkins Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-2102)