Skip to content
General Revolution Evolution Add-ons International
Login | Register | MODX.com
MODX Open Source Content Management System, Framework, Platform and More.
Find a Partner | Hosts + SaaS | Jobs | Donate
  • RegisterSign Up with the MODX Community
  • LoginUse Your MODX.com Account
  • MODX Community Forums
  • General
  • Security Notices
  •  
  • MODx Revolution Cross-Site Scripting and Local File Inclusion Vulnerabilities#

  • 27708
    1,811
    - Dir. Channels & Community

    Jay Gilmore Reply #1, 1 year, 7 months ago

    Reply
    • Link to this post#1
    Status: Solved (See: Notice on fix)
    Product: MODx Revolution
    Risk: Moderate
    Versions: 2.0.x
    Vunerability type: Cross-Site Scripting and Local File Inclusion Vulnerabilities
    Report Date: 2010-09-29
    Fixed Date: 2010-09-29

    Description
    Issue reported as Secunia Advisory SA41638.

    Input passed via the "modahsh" parameter to manager/index.php is not properly sanitized before being returned to the user and input passed via the "class_key" parameter to manager/controllers/default/resource/tvs.php is not properly verified before being used to include files.


    Affected Releases
    MODx Revolution 2.0.2-pl however it is possible previous releases contain the vulnerability.

    Solution
    Upgrade to MODx Revolution 2.0.3 available here: http://modxcms.com/download.html#pl Read the Release Announcement for Revolution 2.0.3.





Actions

Login to Post

Other Support Options

To file a bug or make a feature request visit our issue tracker, or you can also purchase commercial support.

Love MODX?

If you build sites for a living with MODX or just love using it, why not give back?

Information

Posted in this thread:
smashingred

 
Back to Top

MODX Global HQ

1333 N Stemmons Fwy, Ste 110
Dallas, TX 75207
United States

+1 (469) 777-MODX (6639)

The MODX Company

  • Contact
  • Media Center
  • Careers at MODX
  • Wall of Fame
  • The MODX Blog

Sponsors

SoftLayer Firehost: Secure Cloud Hosting

Stay Connected

Read our previous email newsletters.

Twitter Facebook Google+ LinkedIn github Feeds

Privacy Policy | Terms of Service | Pixels by AKTA Web Studio© 2005-2012 MODX. All rights reserved. Trademark Policy