Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0094 (MODxCMS)

BugsAlert Home > CVE-2008-0094 (MODxCMS)
 
 

Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0094

Learn more about CVE-2008-0094 (MODxCMS)
 
Tags: cve-2008-0094 modxcms

Related Items

      CVE-2007-6092 (Ingate Firewall, Ingate SIParator)

      CVE-2008-2244 (office_word)

      MS07-012: Vulnerability in Microsoft MFC Could Allow Remote Code Execution (924667) - Version:2.1

      FrSIRT - Debian Security Update Fixes Xulrunner Code Execution Vulnerability

      Bugtraq: [SECURITY] [DSA 1475-1] new gforge packages fix cross site scripting

      Debian: New iceweasel packages fix several vulnerabilities

      Fedora update for asterisk

 

Pixel