WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2013-07-08T20:00:00
Updated: 2013-08-13T09:00:00
Reserved: 2013-02-19T00:00:00
Link: CVE-2013-2203
JSON object: View
NVD Information
Status : Analyzed
Published: 2013-07-08T20:55:01.103
Modified: 2013-09-10T17:12:07.770
Link: CVE-2013-2203
JSON object: View
Redhat Information
No data.
CWE