Vulnerabilities > CVE-2007-0659 - Unspecified vulnerability in Modxcms Filedownload 1.7/2.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://modxcms.com/forums/index.php/topic%2C10470.0.html
- http://modxcms.com/forums/index.php/topic%2C10470.0.html
- http://secunia.com/advisories/23953
- http://secunia.com/advisories/23953
- http://www.muddydogpaws.com/Home.html
- http://www.muddydogpaws.com/Home.html
- http://www.securityfocus.com/bid/22327
- http://www.securityfocus.com/bid/22327
- http://www.vupen.com/english/advisories/2007/0426
- http://www.vupen.com/english/advisories/2007/0426