Show filters
62 Total Results
Displaying 41-50 of 62
Sort by:
Attacker Value
Unknown

CVE-2014-2080

Disclosure Date: March 01, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter.
0
Attacker Value
Unknown

CVE-2010-5278

Disclosure Date: October 07, 2012 (last updated October 05, 2023)
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-4883

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter.
0
Attacker Value
Unknown

CVE-2010-3929

Disclosure Date: February 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
0
Attacker Value
Unknown

CVE-2011-0741

Disclosure Date: February 02, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor.
0
Attacker Value
Unknown

CVE-2010-3930

Disclosure Date: February 02, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE-2010-1427.
0
Attacker Value
Unknown

CVE-2010-1426

Disclosure Date: April 15, 2010 (last updated October 04, 2023)
SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin.
0
Attacker Value
Unknown

CVE-2010-1427

Disclosure Date: April 15, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to AjaxSearch.
0
Attacker Value
Unknown

CVE-2008-7243

Disclosure Date: September 17, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords via manager/index.php. NOTE: due to the lack of details, it is not clear whether this is related to CVE-2008-5941.
0
Attacker Value
Unknown

CVE-2008-7242

Disclosure Date: September 17, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachable from manager/index.php; (5) highlight, (6) id, (7) email, (8) name, and (9) parent parameters to index.php; and the (10) docgrp and (11) moreResultsPage parameters to index-ajax.php.
0