A few days ago, Magento 1.7.0.2 was released to fix a very serious security vulnerability that allows attackers to read any file on the web server where the Zend XMLRPC functionality is enabled. This might include password files, configuration files, and possibly even databases if they are stored on the same machine as the Magento web server.
The Magento team provides the following info in their post:
If the patch cannot be applied immediately, the following instructions can be followed to temporarily disable the RPC functionality that contains the vulnerability. Please be advised, any integrations that rely on the XMLRPC API functionality will no longer work after this workaround is implemented.
1. On the Magento web server, navigate to the www-root where Magento app files are stored.
2. In the wwwroot, navigate to /app/code/core/Mage/Api/controllers.
3. Open XmlrpcController.php for editing.
4. Comment out or delete the body of the method: public indexAction()
5. Save the changes.*The latest releases of Magento (Community Edition 1.7.0.2 and Enterprise Edition 1.12.0.2) incorporate the appropriate patches. please use correct versions of releases 1.7.0.2 and 1.12.0.2 .
Note: This vulnerability comes from Zend_XmlRpc, so not only Magento, but any application that uses it is vulnerable. More details about it here:
Zend_XmlRpc is vulnerable to XML eXternal Entity (XXE) Injection attacks. The SimpleXMLElement class (SimpleXML PHP extension) is used in an insecure way to parse XML data. External entities can be specified by adding a specific DOCTYPE element to XML-RPC requests. By exploiting this vulnerability an application may be coerced to open arbitrary files and/or TCP connections.
Additional details are also available here.
If you have any additional information, make sure to leave a comment. Want to chat with us? Send us an email to info@sucuri.net.
2 comments
Yes, the cloud
feature allows you to have your profiles on both Xboxs without recovering
each time. You can even store your profile on friends consoles and access
your cloud saves without having to recover each time. I no longer use a thumb
drive for my saves and profile.
I going to upgrade Magento to 1.7 after New Year, Searching ar Magento.commerce forum, I had found Cart2Cart service http://www.shopping-cart-migration.com/shopping-cart-migration-options/223-magento-to-magento-migration . They say it migrate all data automatically to the new version, and give this service a nice feedback. I don’t want to waste my time transferring all data manually, so any opinion according this?
Comments are closed.