CVE-2011-3818
WordPress 2.9.2 and 3.0.4 - Exposure of Sensitive Information via Direct Request to .php Files
Title source: llmDescription
WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.
References (3)
Core 3
Core References
Issue Tracking x_refsource_misc
http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/%21_README
Issue Tracking x_refsource_misc
http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/wordpress_2.9.2
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/06/27/6
Scores
EPSS
0.0050
EPSS Percentile
66.1%
Details
CWE
CWE-200
Status
published
Products (2)
wordpress/wordpress
2.9.2
wordpress/wordpress
3.0.4
Published
Sep 24, 2011
Tracked Since
Feb 18, 2026