download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2007/0426 | vdb entry |
http://secunia.com/advisories/23953 | patch vendor advisory third party advisory |
http://modxcms.com/forums/index.php/topic%2C10470.0.html | |
http://www.muddydogpaws.com/Home.html | |
http://www.securityfocus.com/bid/22327 | patch vdb entry |