MODX Revolution Multiple Vulnerabilities
BID:70901
Info
MODX Revolution Multiple Vulnerabilities
| Bugtraq ID: | 70901 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8773 CVE-2014-8774 CVE-2014-8775 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2014 12:00AM |
| Updated: | Dec 05 2014 12:58AM |
| Credit: | Narendra Bhati |
| Vulnerable: |
MODx MODx Revolution 2.2.0 |
| Not Vulnerable: | |
Discussion
MODX Revolution Multiple Vulnerabilities
MODX Revolution is prone to the following vulnerabilities:
1. A cross-site scripting vulnerability
2. An HTML-injection vulnerability
3. A security-bypass vulnerability
Attackers can exploit these issues to steal cookie-based authentication credentials, to execute arbitrary local scripts in the context of the web server process, or to execute arbitrary code in the context of the affected application and to bypass certain security restrictions and perform unauthorized actions.
Versions prior to MODX Revolution 2.2.15 are vulnerable.
MODX Revolution is prone to the following vulnerabilities:
1. A cross-site scripting vulnerability
2. An HTML-injection vulnerability
3. A security-bypass vulnerability
Attackers can exploit these issues to steal cookie-based authentication credentials, to execute arbitrary local scripts in the context of the web server process, or to execute arbitrary code in the context of the affected application and to bypass certain security restrictions and perform unauthorized actions.
Versions prior to MODX Revolution 2.2.15 are vulnerable.
Exploit / POC
MODX Revolution Multiple Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
MODX Revolution Multiple Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
MODX Revolution Multiple Vulnerabilities
References:
References: