WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Wordpress | Wordpress | 2.0 (including) | 2.0 (including) |
| Wordpress | Wordpress | 2.0.1 (including) | 2.0.1 (including) |
| Wordpress | Wordpress | 2.0.2 (including) | 2.0.2 (including) |
| Wordpress | Wordpress | 2.0.3 (including) | 2.0.3 (including) |
| Wordpress | Wordpress | 2.0.4 (including) | 2.0.4 (including) |
| Wordpress | Wordpress | 2.0.5 (including) | 2.0.5 (including) |
| Wordpress | Wordpress | 2.0.6 (including) | 2.0.6 (including) |
| Wordpress | Wordpress | 2.0.7 (including) | 2.0.7 (including) |
| Wordpress | Wordpress | 2.1 (including) | 2.1 (including) |
| Wordpress | Wordpress | 2.1.1 (including) | 2.1.1 (including) |