MediaWiki 1.8.1, and other versions before 1.13.3, when the wgShowExceptionDetails variable is enabled, sometimes provides the full installation path in a debugging message, which might allow remote attackers to obtain sensitive information via unspecified requests that trigger an uncaught exception.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html | vendor advisory |
http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html | mailing list vendor advisory |
http://www.mediawiki.org/wiki/Manual:%24wgShowExceptionDetails | |
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html | vendor advisory |
http://secunia.com/advisories/33349 | third party advisory vendor advisory |