MODX Evolution Multiple Cross-Site Scripting and Command Injection Vulnerabilities
BID:70999
Info
MODX Evolution Multiple Cross-Site Scripting and Command Injection Vulnerabilities
| Bugtraq ID: | 70999 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2014 12:00AM |
| Updated: | Nov 06 2014 12:00AM |
| Credit: | Karthik Rangarajan |
| Vulnerable: |
MODx MODx Evolution 1.0.14 MODx MODx Evolution 1.0.7 MODx MODx Evolution 1.0.6 MODx MODx Evolution 1.0.5 MODx MODx Evolution 1.0.4 MODx MODx Evolution 1.0.3 MODx MODx Evolution 1.0.2 MODx MODx 0.9.6 .3 MODx MODx 0.9.6 .2 MODx MODx 0.9.6 .1p1 MODx MODx 0.9.6 .1 MODx MODx 0.9.6 |
| Not Vulnerable: |
MODx MODx Evolution 1.0.15 |
Exploit / POC
MODX Evolution Multiple Cross-Site Scripting and Command Injection Vulnerabilities
Attackers can exploit these issues with a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues with a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
MODX Evolution Multiple Cross-Site Scripting and Command Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
MODX Evolution Multiple Cross-Site Scripting and Command Injection Vulnerabilities
References:
References:
- Modx Home Page (Modx)
- Multiple Vulnerabilities XSS/Remote Command Injection (Karthik Rangarajan)