CVE-2008-0195
Publication date 10 January 2008
Last updated 24 July 2024
Ubuntu priority
Description
WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.