Description
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-PostRatings '[ratings]' Shortcode SQL Injection (1.61)
WordPress Plugin WP Super Cache Cross-Site Scripting (1.3)
WordPress Plugin Download Theme Arbitrary Directory Download (1.0.2)
WordPress 4.0.x Possible SQL Injection Vulnerability (4.0 - 4.0.19)
Oracle Database Server CVE-2006-0266 Vulnerability (CVE-2006-0266)