Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Evolution HIGH 7.5
CVE-2010-3929

SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related…

Fix: after 1.0.4
Fix from $1,950 2011-02-02
Evolution MEDIUM 5.0
CVE-2010-3930

Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related…

Fix: after 1.0.4
Fix from $1,600 2011-02-02
Modxcms HIGH 7.5
CVE-2010-1426

SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to W…

Fix: after 1.0.2
Fix from $1,950 2010-04-15
Modxcms MEDIUM 6.8
CVE-2008-7243

Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of …

No fix yet
Fix from $1,600 2009-09-17
Modxcms MEDIUM 6.8
CVE-2008-5940

SQL injection vulnerability in index.php in MODx 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary…

Fix: after 0.9.6.2
Fix from $1,600 2009-01-22
Modxcms MEDIUM 6.0
CVE-2008-5941

Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized actions as other users …

Fix: after 0.9.6.1
Fix from $1,600 2009-01-22
Modxcms MEDIUM 6.8
CVE-2008-5938

PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disa…

Fix: after 0.9.6.2
Fix from $1,600 2009-01-22
Modxcms MEDIUM 6.4
CVE-2008-0094

Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary lo…

Patch available
Fix from $1,600 2008-01-08
Modxcms MEDIUM 6.8
CVE-2007-5371

Multiple SQL injection vulnerabilities in mutate_content.dynamic.php in MODx 0.9.6 allow remote attackers to execute arbitrary SQL commands via the (…

Mitigation only
Fix from $1,600 2007-10-11
Filedownload HIGH 7.5
CVE-2007-0659

download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by dow…

Patch available
Fix from $1,950 2007-02-01
Modxcms MEDIUM 5.1
CVE-2006-5730

PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows r…

Fix: after 0.9.2.1
Fix from $1,600 2006-11-06
Modxcms MEDIUM 6.4
CVE-2006-1821

Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing…

Mitigation only
Fix from $1,600 2006-04-18
Modxcms MEDIUM 5.8
CVE-2006-1820

Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id paramet…

No fix yet
Fix from $1,600 2006-04-18