Modx Revolution 'modX::_initContext()' Method SQL Injection Vulnerability
BID:66162
Info
Modx Revolution 'modX::_initContext()' Method SQL Injection Vulnerability
| Bugtraq ID: | 66162 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2014 12:00AM |
| Updated: | Mar 07 2014 12:00AM |
| Credit: | Mark Ernst |
| Vulnerable: |
MODx MODx Revolution 2.0.2 pl1 MODx MODx Revolution 2.2.9 MODx MODx Revolution 2.2.8 MODx MODx Revolution 2.2.7 MODx MODx Revolution 2.2.6 MODx MODx Revolution 2.2.5 MODx MODx Revolution 2.2.4 MODx MODx Revolution 2.2.3 MODx MODx Revolution 2.2.2 MODx MODx Revolution 2.2.12 MODx MODx Revolution 2.2.11 MODx MODx Revolution 2.2.10 MODx MODx Revolution 2.2.1 MODx MODx Revolution 2.2.0 MODx MODx Revolution 2.1.5 MODx MODx Revolution 2.1.4 MODx MODx Revolution 2.1.3 MODx MODx Revolution 2.1.2 MODx MODx Revolution 2.1.1 MODx MODx Revolution 2.1.0 MODx MODx Revolution 2.0.8 MODx MODx Revolution 2.0.7 MODx MODx Revolution 2.0.6 MODx MODx Revolution 2.0.5 MODx MODx Revolution 2.0.4 MODx MODx Revolution 2.0.3 MODx MODx Revolution 2.0.1 MODx MODx Revolution 2.0.0 |
| Not Vulnerable: |
MODx MODx Revolution 2.2.13 |
Discussion
Modx Revolution 'modX::_initContext()' Method SQL Injection Vulnerability
Modx Revolution is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Modx Revolution 2.2.13 are vulnerable.
Modx Revolution is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Modx Revolution 2.2.13 are vulnerable.
Exploit / POC
Modx Revolution 'modX::_initContext()' Method SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.