First published: Thu Feb 01 2007(Updated: )
download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MODX CMS File Download | =1.7 | |
MODX CMS File Download | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0659 has a severity rating that reflects its potential to allow remote attackers to access sensitive files on affected systems.
To fix CVE-2007-0659, update to version 2.5 or later of the MuddyDogPaws FileDownload snippet for MODx.
CVE-2007-0659 affects versions 1.7 and 2.0 of the MuddyDogPaws FileDownload snippet for MODx.
Exploiting CVE-2007-0659 allows an attacker to download arbitrary files, which could lead to exposure of sensitive information such as database credentials.
If you cannot update to a fixed version, consider restricting access to the download.php file or implementing additional security measures to minimize risk.