Перейти к содержимому
Noroxi

Записи modx

44 опубликованных записей вендора modx.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
7
С записью об исправлении
31,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

44 записей
  • CVE-2018-1000207
    47В плане

    MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt

    ВысокаяCVSS 7,2Эксплойта нетEPSS 64 %

    modx · modx revolution13 июл. 2018 г.

  • CVE-2019-1010178
    40В плане

    Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    modx · fred24 июл. 2019 г.

  • CVE-2017-7324
    40В плане

    setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    modx · modx revolution30 мар. 2017 г.

  • CVE-2017-7321
    40В плане

    setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_k

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    modx · modx revolution30 мар. 2017 г.

  • CVE-2020-25911
    37Наблюдать

    A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an infor

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    modx · modx revolution31 окт. 2021 г.

  • CVE-2017-9069
    36Наблюдать

    In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .ht

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    modx · modx revolution18 мая 2017 г.

  • CVE-2017-1000067
    35Наблюдать

    MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    modx · revolution17 июл. 2017 г.

  • CVE-2017-7323
    33Наблюдать

    The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allo

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    modx · modx revolution30 мар. 2017 г.

  • CVE-2017-7322
    32Наблюдать

    The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL serve

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    modx · modx revolution30 мар. 2017 г.

  • CVE-2022-26149
    31Наблюдать

    MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, becau

    ВысокаяCVSS 7,2Proof of conceptEPSS 9 %

    modx · revolution26 февр. 2022 г.

  • CVE-2018-1000208
    31Наблюдать

    MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    modx · modx revolution13 июл. 2018 г.

  • CVE-2016-10038
    30Наблюдать

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    ВысокаяCVSS 7,3Эксплойта нетEPSS 2 %

    modx · modx revolution24 дек. 2016 г.

  • CVE-2016-10037
    30Наблюдать

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    ВысокаяCVSS 7,3Эксплойта нетEPSS 2 %

    modx · modx revolution24 дек. 2016 г.

  • CVE-2016-10039
    30Наблюдать

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    ВысокаяCVSS 7,3Эксплойта нетEPSS 2 %

    modx · modx revolution24 дек. 2016 г.

  • CVE-2014-2736
    30Наблюдать

    Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1)

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    modx · modx revolution24 апр. 2014 г.

  • CVE-2014-2311
    30Наблюдать

    SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL comman

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    modx · modx revolution11 мар. 2014 г.

  • CVE-2019-1010123
    30Наблюдать

    MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    modx · modx revolution23 июл. 2019 г.

  • CVE-2017-9067
    28Наблюдать

    In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to

    ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %

    modx · modx revolution18 мая 2017 г.

  • CVE-2014-8773
    27Наблюдать

    MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitti

    СредняяCVSS 6,8Proof of conceptEPSS 1 %

    modx · modx revolution3 дек. 2014 г.

  • CVE-2015-6588
    24Наблюдать

    Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web s

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    modx · modx revolution29 авг. 2017 г.

  • CVE-2017-7320
    24Наблюдать

    setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remo

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    modx · modx revolution30 мар. 2017 г.

  • CVE-2018-20755
    24Наблюдать

    MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    modx · modx revolution6 февр. 2019 г.

  • CVE-2018-20757
    24Наблюдать

    MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    modx · modx revolution6 февр. 2019 г.

  • CVE-2018-20756
    24Наблюдать

    MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Qui

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    modx · modx revolution6 февр. 2019 г.

  • CVE-2017-9068
    24Наблюдать

    In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, a

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    modx · modx revolution18 мая 2017 г.