PT-2007-2113 · Modx · Muddydogpaws Filedownload
Published
2007-02-01
·
Updated
2011-03-08
·
CVE-2007-0659
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MuddyDogPaws FileDownload snippet versions prior to 2.5 for MODx
Description
The issue allows remote attackers to download arbitrary files. This can be demonstrated by downloading config.inc.php to obtain database credentials.
Recommendations
For versions prior to 2.5, consider restricting access to the download.php file until a patch is available. As a temporary workaround, avoid using the download.php file in the MuddyDogPaws FileDownload snippet to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Muddydogpaws Filedownload