Title : MuddyDogPaws FileDownload "download.php" Arbitrary File Download Vulnerability VUPEN ID : VUPEN/ADV-2007-0426 CVE ID : CVE-2007-0659
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-31
Technical Description
A vulnerability has been identified in MuddyDogPaws FileDownload, which could be exploited by attackers to gain knowledge of sensitive information. This issue is due to an input validation error in the "download.php" script that does not validate user-supplied parameters, which could be exploited by malicious users to download arbitrary files from a vulnerable web server.