Description
Magento stores its configuration in a file local.xml. Due to a misconfiguration of a web server, an attacker can access the cofiguration file.
Remediation
Restrict access to local.xml
References
Related Vulnerabilities
Multiple vulnerabilities in Ioncube loader-wizard.php
WordPress Plugin User Profile Picture Information Disclosure (2.4.0)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-0815)
WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.27)
WordPress Plugin Zip Attachments Arbitrary File Download (1.4)