CVE-2006-6017
published 2006-11-21CVE-2006-6017: WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to…
medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.26%
81.0th percentile
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.0.5-0.1 (bookworm) | wordpress 2.0.5-0.1 (bookworm) |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
cvelistv56.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WordPress 2.0.5 Serialization denial of service
vuldb·2026-04-28·CVSS 6.5
CVE-2006-6017 [MEDIUM] WordPress 2.0.5 Serialization denial of service
A vulnerability was found in WordPress 2.0.5. It has been rated as problematic. This vulnerability affects unknown code of the component Serialization. This manipulation causes denial of service.
This vulnerability is registered as CVE-2006-6017. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
GHSA-57qp-9wm8-fgr9: WordPress before 2
ghsa_unreviewed·2022-05-01
CVE-2006-6017 [MEDIUM] CWE-400 GHSA-57qp-9wm8-fgr9: WordPress before 2
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
OSV
CVE-2006-6017: WordPress before 2
osv·2006-11-21·CVSS 6.5
CVE-2006-6017 [MEDIUM] CVE-2006-6017: WordPress before 2
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
CVEList
CVE-2006-6017: WordPress before 2
cvelistv5·2006-11-21·CVSS 6.5
CVE-2006-6017 [MEDIUM] CVE-2006-6017: WordPress before 2
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
Debian
CVE-2006-6017: wordpress - WordPress before 2.0.5 does not properly store a profile containing a string rep...
vendor_debian·2006·CVSS 6.5
CVE-2006-6017 [MEDIUM] CVE-2006-6017: wordpress - WordPress before 2.0.5 does not properly store a profile containing a string rep...
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
Scope: local
bookworm: resolved (fixed in 2.0.5-0.1)
bullseye: resolved (fixed in 2.0.5-0.1)
forky: resolved (fixed in 2.0.5-0.1)
sid: resolved (fixed in 2.0.5-0.1)
trixie: resolved (fixed in 2.0.5-0.1)
No detection rules found.
No public exploits indexed.
2006-11-21
Published