In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-05-18T16:00:00Z

Updated: 2024-09-16T23:41:54.958Z

Reserved: 2017-05-18T00:00:00Z

Link: CVE-2017-9069

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-05-18T16:29:00.220

Modified: 2017-05-30T19:05:15.980

Link: CVE-2017-9069

cve-icon Redhat

No data.