CVE-2014-2736
Summary
| CVE | CVE-2014-2736 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-24 14:55:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id parameter to manager/index.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Modx | Modx Revolution | 2.0.0 | All | All | All |
| Application | Modx | Modx Revolution | 2.0.1 | All | All | All |
| Application | Modx | Modx Revolution | 2.0.3 | All | All | All |
| Application | Modx | Modx Revolution | 2.0.4 | All | All | All |
| Application | Modx | Modx Revolution | 2.0.5 | All | All | All |
| Application | Modx | Modx Revolution | 2.0.6 | All | All | All |
| Application | Modx | Modx Revolution | 2.0.7 | All | All | All |
| Application | Modx | Modx Revolution | 2.0.8 | All | All | All |
| Application | Modx | Modx Revolution | 2.1.0 | All | All | All |
| Application | Modx | Modx Revolution | 2.1.1 | All | All | All |
| Application | Modx | Modx Revolution | 2.1.2 | All | All | All |
| Application | Modx | Modx Revolution | 2.1.3 | All | All | All |
| Application | Modx | Modx Revolution | 2.1.4 | All | All | All |
| Application | Modx | Modx Revolution | 2.1.5 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.0 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.1 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.10 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.11 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.12 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.2 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.3 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.4 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.5 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.6 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.7 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.8 | All | All | All |
| Application | Modx | Modx Revolution | 2.2.9 | All | All | All |
| Application | Modx | Modx Revolution | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MODX Revolution 2.2.13 (and prior) Blind SQL Injection | MODX Community Forums | af854a3a-2127-422b-91ae-364da2661108 | forums.modx.com | Vendor Advisory |
| Security Advisory SA58036 - MODx Multiple SQL Injection Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| MODx Revolution Multiple SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.