MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2013-4301
includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8 1.20.x before 1.20.7 and 1.21.x before 1.21.2 allows remote attackers to obtain sensitive information via a quotltquot (open angle bracket) character in the lang parameter to w/load.php which reveals the installation path in an error message.