download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.
References
Link | Resource |
---|---|
http://modxcms.com/forums/index.php/topic,10470.0.html | Vendor Advisory |
http://www.muddydogpaws.com/Home.html | |
http://www.securityfocus.com/bid/22327 | Patch |
http://secunia.com/advisories/23953 | Patch Vendor Advisory |
http://www.vupen.com/english/advisories/2007/0426 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-02-01 14:28
Updated : 2011-03-07 18:50
NVD link : CVE-2007-0659
Mitre link : CVE-2007-0659
JSON object : View
CWE
Products Affected
modxcms
- filedownload