Description
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
Remediation
References
Related Vulnerabilities
Contao Incorrect Default Permissions Vulnerability (CVE-2019-19712)
WordPress Plugin CM Ad Changer Cross-Site Scripting (1.7.7)
WordPress Plugin Contest Gallery-Photo Contest for WordPress Cross-Site Request Forgery (10.4.1.1)
WordPress Plugin Subscriptions & Memberships for PayPal Cross-Site Scripting (1.1.2)