
CVE-2017-7322
https://notcve.org/view.php?id=CVE-2017-7322
30 Mar 2017 — The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code via a crafted certificate. Las funcionalidades (1) update y (2) package-installation features en MODX Revolution 2.5.4-pl y versiones anteriores no verifican certificados X.509 de servidores SSL, lo que permite a atacantes man-in-the-middle falsificar servidores y a... • http://www.securityfocus.com/bid/97228 • CWE-295: Improper Certificate Validation •

CVE-2017-7323
https://notcve.org/view.php?id=CVE-2017-7323
30 Mar 2017 — The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code by leveraging the lack of the HTTPS protection mechanism. Las funcionalidades (1) update y (2) package-installation en MODX Revolution 2.5.4-pl y versiones anteriores utiliza por defecto http://rest.modx.com, lo que permite a atacantes man-in-the-middle suplantar servidores y des... • http://www.securityfocus.com/bid/97228 •

CVE-2017-7324
https://notcve.org/view.php?id=CVE-2017-7324
30 Mar 2017 — setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter. setup/templates/findcore.php en MODX Revolution 2.5.4-pl y versiones anteriores permite a atacantes remotos ejecutar código arbitrario PHP a través del parámetro core_path. • http://www.securityfocus.com/bid/97228 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2016-10037
https://notcve.org/view.php?id=CVE-2016-10037
24 Dec 2016 — Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist. Salto de directorio en /connectors/index.php en MODX Revolution en versiones anteriores a 2.5.2-pl permite a atacantes remotos llevar a cabo inclusión/salto/manipulación de archivo local local a través de un parámetro id manipulado (también conocido como dir), relacionado con ... • http://www.securityfocus.com/bid/95127 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2016-10038
https://notcve.org/view.php?id=CVE-2016-10038
24 Dec 2016 — Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove. Salto de directorio en /connectors/index.php en MODX Revolution en versiones anteriores a 2.5.2-pl permite a atacantes remotos llevar a cabo inclusión/salto/manipulación de archivo local a través de un parámetro dir manipulado, relacionado con navegador/directorio/suprimir. • http://www.securityfocus.com/bid/95097 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2016-10039
https://notcve.org/view.php?id=CVE-2016-10039
24 Dec 2016 — Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles. Salto de directorio en /connectors/index.php en MODX Revolution en versiones anteriores a 2.5.2-pl permite a atacantes remotos llevar a cabo inclusión/salto/manipulación de archivo local a través de un parámetro dir manipulado, relacionado con navegador/directorio/obtener archivos. • http://www.securityfocus.com/bid/95096 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2015-6588 – MODX Login Extra Cross Site Scripting
https://notcve.org/view.php?id=CVE-2015-6588
24 Nov 2015 — Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en login-fsp.html en MODX Revolution en versiones anteriores a la 1.9.01 permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante el parámetro QUERY_STRING. MODX Login Extra versions prior to 1.9.1 suffer from a cross site scripting vulnerability. • https://packetstorm.news/files/id/134529 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-8992
https://notcve.org/view.php?id=CVE-2014-8992
22 Dec 2014 — Cross-site scripting (XSS) vulnerability in manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution 2.3.2-pl allows remote attackers to inject arbitrary web script or HTML via the callback parameter. Vulnerabilidad XSS en in manager/assets/fileapi/FileAPI.flash.image.swf en MODX Revolution 2.3.2-pl, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un parámetro de devolución de la llamada. • https://github.com/modxcms/revolution/issues/12161 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-8773 – MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2014-8773
03 Dec 2014 — MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CSRF token or via a (2) long string in the CSRF token parameter. MODX Revolution 2.x anterior a 2.2.15 permite a atacantes remotos evadir el mecanismo de protección de CSRF mediante la (1) omisión del token CSRF o a través de una (2) cadena larga en el parámetro del token CSRF. • https://www.exploit-db.com/exploits/35159 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-8774 – MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2014-8774
03 Dec 2014 — Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter. Vulnerabilidad de XSS en manager/index.php en MODX Revolution 2.x anterior a 2.2.15 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro context_key. • https://www.exploit-db.com/exploits/35159 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •