To add some more security to MODx I would recommend to insert the following lines in index.php just after line 50:
// Secure variables from outside
foreach(array('HTTP_REFERER','HTTP_USER_AGENT') as $outside) {
$_SERVER[$outside] = preg_replace("/[^A-Za-z0-9_\-\,\.\/\s]/", "", $_SERVER[$outside]);
if(strlen($_SERVER[$outside])>255) $_SERVER[$outside] = substr(0,255,$_SERVER[$outside]);
}
if(isset($_GET['q'])) $_GET['q'] = preg_replace("/[^A-Za-z0-9_\-\.\/]/", "", $_GET['q']);
// Never allow request via get and post contain snippets, javascript or php
$modxtags = array('@<script[^>]*?>.*?</script>@si',
'@&#(\d+);@e',
'@\[\[(.*?)\]\]@si',
'@\[!(.*?)!\]@si',
'@\[\~(.*?)\~\]@si',
'@\[\((.*?)\)\]@si',
'@{{(.*?)}}@si',
'@\[\*(.*?)\*\]@si');
foreach($_POST as $key => $value) {
$_POST[$key] = preg_replace($modxtags,"", $value);
}
foreach($_GET as $key => $value) {
$_GET[$key] = preg_replace($modxtags,"", $value);
}
// End of modification
It isn’t substantially tested, but it’s a good start.