CVE-2012-3829 - Preventable Aircraft
Description
Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header.
Reference
http://packetstormsecurity.org/files/112249/Joomla-2.5.3-Host-Header-Cross-Site-Scripting.html