Description Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header. Remediation References CVE-2012-3829 Related Vulnerabilities WordPress Plugin WP eCommerce 'cs1' Parameter SQL Injection (3.8.6) WordPress Plugin CBX Bookmark & Favorite Cross-Site Scripting (1.6.8) PHP Out-of-bounds Write Vulnerability (CVE-2016-7127) WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.39) Apache Tomcat version older than 4.1.39 Severity Medium Classification CVE-2012-3829 CWE-200 Tags Missing Update Known Vulnerabilities