Описание
MODX Revolution allows overwriting .htaccess
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.
Пакеты
Наименование
modx/revolution
composer
Затронутые версииВерсия исправления
< 2.5.7
2.5.7
Связанные уязвимости
CVSS3: 8.8
nvd
около 8 лет назад
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.