Description
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Filter SQL Injection (1.5)
WordPress Plugin AllWebMenus WordPress Menu 'actions.php' Arbitrary File Upload (1.1.8)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.68)
WordPress Plugin Advanced Post Type Ratings Cross-Site Scripting (1.01)