İçeriğe atla
Noroxi

modx kayıtları

modx üreticisine ait 44 yayımlanmış kayıt.

Tüm kayıtlar

44 kayıt
  • CVE-2018-1000207
    47Planlayın

    MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt

    YüksekCVSS 7,2İstismar yokEPSS %64

    modx · modx revolution13 Tem 2018

  • CVE-2019-1010178
    40Planlayın

    Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.

    KritikCVSS 9,8İstismar yokEPSS %5

    modx · fred24 Tem 2019

  • CVE-2017-7324
    40Planlayın

    setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path

    KritikCVSS 9,8İstismar yokEPSS %2

    modx · modx revolution30 Mar 2017

  • CVE-2017-7321
    40Planlayın

    setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_k

    KritikCVSS 9,8İstismar yokEPSS %2

    modx · modx revolution30 Mar 2017

  • CVE-2020-25911
    37İzleyin

    A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an infor

    KritikCVSS 9,1İstismar yokEPSS %2

    modx · modx revolution31 Eki 2021

  • CVE-2017-9069
    36İzleyin

    In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .ht

    YüksekCVSS 8,8İstismar yokEPSS %2

    modx · modx revolution18 May 2017

  • MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in a

    YüksekCVSS 8,8İstismar yokEPSS %1

    modx · revolution17 Tem 2017

  • CVE-2017-7323
    33İzleyin

    The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allo

    YüksekCVSS 8,1İstismar yokEPSS %2

    modx · modx revolution30 Mar 2017

  • CVE-2017-7322
    32İzleyin

    The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL serve

    YüksekCVSS 8,1İstismar yokEPSS %1

    modx · modx revolution30 Mar 2017

  • CVE-2022-26149
    31İzleyin

    MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, becau

    YüksekCVSS 7,2Kavram kanıtıEPSS %9

    modx · revolution26 Şub 2022

  • MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result

    YüksekCVSS 7,5İstismar yokEPSS %2

    modx · modx revolution13 Tem 2018

  • CVE-2016-10038
    30İzleyin

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    YüksekCVSS 7,3İstismar yokEPSS %2

    modx · modx revolution24 Ara 2016

  • CVE-2016-10037
    30İzleyin

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    YüksekCVSS 7,3İstismar yokEPSS %2

    modx · modx revolution24 Ara 2016

  • CVE-2016-10039
    30İzleyin

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    YüksekCVSS 7,3İstismar yokEPSS %2

    modx · modx revolution24 Ara 2016

  • CVE-2014-2736
    30İzleyin

    Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1)

    YüksekCVSS 7,5İstismar yokEPSS %1

    modx · modx revolution24 Nis 2014

  • CVE-2014-2311
    30İzleyin

    SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL comman

    YüksekCVSS 7,5İstismar yokEPSS %1

    modx · modx revolution11 Mar 2014

  • MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type.

    YüksekCVSS 7,5İstismar yokEPSS %1

    modx · modx revolution23 Tem 2019

  • CVE-2017-9067
    28İzleyin

    In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to

    YüksekCVSS 7,0İstismar yokEPSS %1

    modx · modx revolution18 May 2017

  • CVE-2014-8773
    27İzleyin

    MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitti

    OrtaCVSS 6,8Kavram kanıtıEPSS %1

    modx · modx revolution3 Ara 2014

  • CVE-2015-6588
    24İzleyin

    Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web s

    OrtaCVSS 6,1İstismar yokEPSS %1

    modx · modx revolution29 Ağu 2017

  • CVE-2017-7320
    24İzleyin

    setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remo

    OrtaCVSS 6,1İstismar yokEPSS %1

    modx · modx revolution30 Mar 2017

  • CVE-2018-20755
    24İzleyin

    MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.

    OrtaCVSS 6,1İstismar yokEPSS %1

    modx · modx revolution6 Şub 2019

  • CVE-2018-20757
    24İzleyin

    MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.

    OrtaCVSS 6,1İstismar yokEPSS %1

    modx · modx revolution6 Şub 2019

  • CVE-2018-20756
    24İzleyin

    MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Qui

    OrtaCVSS 6,1İstismar yokEPSS %1

    modx · modx revolution6 Şub 2019

  • CVE-2017-9068
    24İzleyin

    In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, a

    OrtaCVSS 6,1İstismar yokEPSS %1

    modx · modx revolution18 May 2017