CVE

Id
62150  
CVE No.
CVE-2013-2203  
Status
Candidate  
Description
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.  
Phase
Assigned (20130219)  
Votes
None (candidate not yet proposed)  
Comments