Description
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
Remediation
References
Related Vulnerabilities
Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-6188)
WordPress Plugin WP-DBManager Arbitrary File Deletion (2.79.1)
Joomla Improper Input Validation Vulnerability (CVE-2011-2892)
WordPress Plugin uContext for Amazon Cross-Site Request Forgery (3.9.1)
WordPress Plugin Knews Multilingual Newsletters 'ff' Parameter Cross-Site Scripting (1.1.0)