Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-6808Cross-site Scripting in Wordpress

6 documents6 sources
Severity
6.8MEDIUMNVD
EPSS
3.5%
top 12.40%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedDec 28
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

debiandebian/wordpress< wordpress 2.0.6-1 (bookworm)
Debianwordpress/wordpress< 2.0.6-1+3
NVDwordpress/wordpress2.0.5+17

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8292-xqwp-qw46: Cross-site scripting (XSS) vulnerability in wp-admin/templates2022-05-01
OSV
CVE-2006-6808: Cross-site scripting (XSS) vulnerability in wp-admin/templates2006-12-28

💥Exploits & PoCs

1
Exploit-DB
WordPress Core 1.x/2.0.x - 'template.php' HTML Injection2006-12-27

📋Vendor Advisories

1
Debian
CVE-2006-6808: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress ...2006

💬Community

1
Bugzilla
CVE-2006-6808: wordpress 2.0.5 XSS vulnerability2006-12-30
CVE-2006-6808 — Cross-site Scripting in Wordpress | cvebase