Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2017-1000067
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.
0
Attacker Value
Unknown
CVE-2014-8774
Disclosure Date: December 03, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter.
0
Attacker Value
Unknown
CVE-2014-8775
Disclosure Date: December 03, 2014 (last updated October 05, 2023)
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
0
Attacker Value
Unknown
CVE-2014-8773
Disclosure Date: December 03, 2014 (last updated October 05, 2023)
MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CSRF token or via a (2) long string in the CSRF token parameter.
0
Attacker Value
Unknown
CVE-2014-2736
Disclosure Date: April 24, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id parameter to manager/index.php.
0
Attacker Value
Unknown
CVE-2014-2311
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-2080
Disclosure Date: March 01, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter.
0
Attacker Value
Unknown
CVE-2011-3201
Disclosure Date: March 08, 2013 (last updated October 05, 2023)
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
0
Attacker Value
Unknown
CVE-2008-1108
Disclosure Date: June 04, 2008 (last updated October 04, 2023)
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
0