7.5
CVE-2007-0659
- EPSS 1.4%
- Veröffentlicht 01.02.2007 22:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Modxcms ≫ Filedownload Version1.7
Modxcms ≫ Filedownload Version2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.4% | 0.69 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://modxcms.com/forums/index.php/topic%2C10470.0.html
http://secunia.com/advisories/23953
http://www.muddydogpaws.com/Home.html
http://www.securityfocus.com/bid/22327
http://www.vupen.com/english/advisories/2007/0426