Description
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2007-2121)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4295)
PHP Other Vulnerability (CVE-2007-1411)
WordPress Plugin Reusable Blocks Extended Cross-Site Request Forgery (0.9)
WordPress Plugin Apptivo Business Site CRM Multiple Cross-Site Scripting Vulnerabilities (1.2.9)