If you are running an archived version of Magento 1.9.0.0, you must apply the SUPEE-5344 shell script patch.
Attackers can extract sensitive database tables, including administrator session hashes, customer personally identifiable information (PII), and encrypted credentials. 3. XML External Entity (XXE) Injection
Ethical hackers use these tools to verify if a client's legacy store is vulnerable during authorized security audits.