9 lines
No EOL
574 B
Text
Executable file
9 lines
No EOL
574 B
Text
Executable file
source: http://www.securityfocus.com/bid/27096/info
|
|
|
|
MODx is prone to a vulnerability that allows attackers to access source code because the application fails to properly sanitize user-supplied input.
|
|
|
|
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
|
|
|
|
MODx 0.9.6.1 is vulnerable; other versions may also be affected.
|
|
|
|
http://www.example.com/modx-0.9.6.1/assets/js/htcmime.php?file=../../manager/includes/config.inc.php%00.htc |