Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.
https://github.com/arkede/cve-2005
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-2613
http://secunia.com/advisories/16386
http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0234.html