CVE-2017-9069: Malicious File Upload
Published May 18, 2017
·Updated
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.
Affected Software
2 affected componentsFixes available
MODx MODX Revolution<=2.5.6
composer/modx/revolution<2.5.7
2.5.7
Remediation
Patch Available
Patch Available
Event History
May 18, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·02:43 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-9069?
CVE-2017-9069 is classified as a medium severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-9069?
To fix CVE-2017-9069, upgrade MODX Revolution to version 2.5.7 or later.
3
Who is affected by CVE-2017-9069?
Any user with file upload permissions on MODX Revolution versions prior to 2.5.7 is affected by CVE-2017-9069.
4
What type of vulnerability is CVE-2017-9069?
CVE-2017-9069 is an arbitrary code execution vulnerability that exploits file upload functionalities.
5
Can CVE-2017-9069 be exploited remotely?
Yes, CVE-2017-9069 can be exploited remotely by an attacker who can upload files to the server.