MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/91847 | vdb entry third party advisory |
https://packetstormsecurity.com/files/125682 | vdb entry third party advisory |
http://www.securityfocus.com/bid/66141 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2014/Mar/102 | third party advisory mailing list |