<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
    <title>Magento Issue Tracking</title>
    <link>http://www.magentocommerce.com/bug-tracking/</link>
    <description></description>
    <dc:language>en</dc:language>
    <dc:creator>MagentoCommerce</dc:creator>
    <dc:rights>Copyright {gmt_date format="%Y"}</dc:rights>
    <dc:date>{gmt_date format="%Y-%m-%dT%H:%i:%s%Q"}</dc:date>
    <admin:generatorAgent rdf:resource="http://expressionengine.com/" />
        <item>
        <title>View Issue #25199 / Security vulnerability in Get.php file allows disc</title>
        <link>http://www.magentocommerce.com/bug-tracking/issue?issue=10863</link>
        <description><![CDATA[<strong>Posted:</strong> 2011-02-09 11:49:00<br/><strong>Category:</strong> Configuration<br/><strong>Version:</strong> 1.5.0.0-rc2<br/><strong>Priority:</strong> urgent<br/><strong>Status:</strong> closed<br/><strong>Reported By:</strong> <a href="http://www.magentocommerce.com/boards/member/147763/">Tom Robertshaw</a></strong><br/><br/>There's a file called get.php in the root of a magento install.  It's purpose seems to be related to loading media images, however it inadvertently allows for database access details to be accessed.<br />
<br />
e.g. visiting http://max.local/magento1500/get.php/app/etc/local.xml shows the entire app/etc/local.xml therefore displaying the database login details and encryption key.<br/><br/><hr/>]]></description>
    </item>
    
                    <item>
        <title>RE: Security vulnerability in Get.php file allows disc</title>
        <description><![CDATA[<em>#1 / Comment by Magento Team</em><br/><br/>Hell Tom,<br />
<br />
We have confirmed this issue and we are already working on it.<br />
<br />
Thank you.]]></description>
    </item>
            <item>
        <title>RE: Security vulnerability in Get.php file allows disc</title>
        <description><![CDATA[<em>#2 / Comment by Magento Team</em><br/><br/>Hello Tom Robertshaw,<br />
<br />
This issue was fixed. Please check the latest Magento release at http://www.magentocommerce.com/download/<br />
<br />
Thank you.]]></description>
    </item>
        </channel>
</rss>