Arbitrary Code Execution via .htaccess File Upload in MODX Revolution

Arbitrary Code Execution via .htaccess File Upload in MODX Revolution

CVE-2017-9069 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.

Learn more about our User Device Pen Test.