CVE-2017-9067
Summary
| CVE | CVE-2017-9067 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-18 16:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal. |
Risk And Classification
Primary CVSS: v3.0 7 HIGH from [email protected]
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-22 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7 | HIGH | CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 4.4 | AV:L/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Modx | Modx Revolution | 2.5.6 | All | All | All |
| Application | Php | Php | 5.3.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY-20] Improve local file inclusion protections by opengeek · Pull Request #13428 · modxcms/revolution · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Third Party Advisory |
| [SECURITY-20] Fix local file inclusion vulnerability in setup action parameter by Mark-H · Pull Request #13422 · modxcms/revolution · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Third Party Advisory |
| MODX Revolution CMS 2.5.6 - Multiple Vulnerabilities - CITADELO | af854a3a-2127-422b-91ae-364da2661108 | citadelo.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.