MediaWiki 1.18.0 allows remote malicious users to obtain the installation path via vectors related to thumbnail creation.
mediawiki mediawiki 1.18.0