Skip to content
General Revolution Evolution Add-ons International
Login | Register | MODX.com
MODX Open Source Content Management System, Framework, Platform and More.
Find a Partner | Hosts + SaaS | Jobs | Donate
  • RegisterSign Up with the MODX Community
  • LoginUse Your MODX.com Account
  • MODX Community Forums
  • General
  • Security Notices
  •  
  • MODx Evo 1.0.4 (and prior) SQL Injection and Directory Traversal Vulnerabities#

  • 21257
    687
    Mike Schell
    Senior Developer, MODX Complete Team
    MODX, LLC

    Email: support@modx.com
    GitHub: https://github.com/netProphET/
    Twitter: @mkschell
    Web: modx.com Tw: @modxcms FB: modxcms

    netProphET - MODX Complete Team Reply #1, 1 year, 3 months ago

    Reply
    • Link to this post#1
    Status: Solved Product: MODx Evolution
    Severity: High
    Versions: 1.0.4 and prior
    Advisory Date: 2011-01-26
    Fixed Date: 2011-01-19
    Impact:
    a) A remote attacker may access or view arbitrary files on the server.
    b) A remote attacker may execute arbitrary PHP code as a result of SQL injection.

    Description JPCERT/CC has issued the following advisories:
    a) http://jvn.jp/en/jp/JVN95385972/index.html
    b) http://jvn.jp/en/jp/JVN54092716/index.html

    Solution Upgrade to MODx Revolution 1.0.5 available here: http://modxcms.com/download.html#ga
    Read the Release Announcement for Evolution 1.0.5.





Actions

Login to Post

Other Support Options

To file a bug or make a feature request visit our issue tracker, or you can also purchase commercial support.

Love MODX?

If you build sites for a living with MODX or just love using it, why not give back?

Information

Posted in this thread:
netProphET

 
Back to Top

MODX Global HQ

1333 N Stemmons Fwy, Ste 110
Dallas, TX 75207
United States

+1 (469) 777-MODX (6639)

The MODX Company

  • Contact
  • Media Center
  • Careers at MODX
  • Wall of Fame
  • The MODX Blog

Sponsors

SoftLayer Firehost: Secure Cloud Hosting

Stay Connected

Read our previous email newsletters.

Twitter Facebook Google+ LinkedIn github Feeds

Privacy Policy | Terms of Service | Pixels by AKTA Web Studio© 2005-2012 MODX. All rights reserved. Trademark Policy