Back to Database
Status published
High
CVE-2007-0659
download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx...
Vulnerability Description
download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0659
Credits & Attribution
No credits recorded in the NVD database.
References
More from modxcms
View All →CVE-2011-0741
Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5...
Medium
4.3
CVE-2010-3930
Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows...
Medium
5
CVE-2010-3929
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows...
High
7.5
CVE-2010-1427
Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx...
Medium
4.3
CVE-2010-1426
SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote...
High
7.5
Affected Vendor
modxcms
View all reports →Affected Software
filedownload
Vulnerable Versions:
1.7, 2.0
Timeline
Official Publish:
February 1st, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.