CVE-2006-1796

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in WordPress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER[‘REQUEST_URI’]).

Date published : 2006-04-17

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=328909

http://trac.wordpress.org/ticket/1686