CVE-2007-0659

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/02/2007
Last modified:
09/04/2025

Description

download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:modxcms:filedownload:1.7:*:*:*:*:*:*:*
cpe:2.3:a:modxcms:filedownload:2.0:*:*:*:*:*:*:*