CVE-2012-1786: Infoleak
Published Mar 19, 2012
·Updated
The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.
Affected Software
10 affected components
Kylegilman Video Embed \& Thumbnail Generator<=1.1
Kylegilman Video Embed \& Thumbnail Generator=0.2
Kylegilman Video Embed \& Thumbnail Generator=0.2.1
Kylegilman Video Embed \& Thumbnail Generator=1.0
Kylegilman Video Embed \& Thumbnail Generator=1.0.1
Kylegilman Video Embed \& Thumbnail Generator=1.0.2
Kylegilman Video Embed \& Thumbnail Generator=1.0.3
Kylegilman Video Embed \& Thumbnail Generator=1.0.4
Kylegilman Video Embed \& Thumbnail Generator=1.0.5
WordPress WordPress
Remediation
Event History
Mar 19, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1786?
The severity of CVE-2012-1786 is classified as medium with a score of 5.
2
What type of vulnerability is CVE-2012-1786?
CVE-2012-1786 is classified as an information leak vulnerability.
3
How do I fix CVE-2012-1786?
To fix CVE-2012-1786, you need to apply the available patch for the Video Embed & Thumbnail Generator plugin.
4
What software is affected by CVE-2012-1786?
CVE-2012-1786 affects the Video Embed & Thumbnail Generator plugin for WordPress before version 2.0.
5
What can attackers achieve with CVE-2012-1786?
Attackers can potentially obtain the installation path of the WordPress site through CVE-2012-1786.