CVE-2013-2203
Publication date 8 July 2013
Last updated 24 July 2024
Ubuntu priority
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.
Status
Package | Ubuntu Release | Status |
---|---|---|
wordpress | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |