Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/57140 | vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/80973 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2013/01/03/10 | third party advisory mailing list |