PT-2007-2113 · Modx · Muddydogpaws Filedownload
Publicado
2007-02-01
·
Atualizado
2011-03-08
·
CVE-2007-0659
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MuddyDogPaws FileDownload snippet versions prior to 2.5 for MODx
Description
The issue allows remote attackers to download arbitrary files. This can be demonstrated by downloading config.inc.php to obtain database credentials.
Recommendations
For versions prior to 2.5, consider restricting access to the download.php file until a patch is available. As a temporary workaround, avoid using the download.php file in the MuddyDogPaws FileDownload snippet to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Muddydogpaws Filedownload