Description
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.
Remediation
References
Related Vulnerabilities
WordPress Plugin Shopping Cart & eCommerce Store Multiple Security Bypass Vulnerabilities (3.0.20)
MediaWiki Other Vulnerability (CVE-2005-2215)
Apache HTTP Server Session Fixation Vulnerability (CVE-2018-17199)
PHP CVE-2006-5706 Vulnerability (CVE-2006-5706)
WordPress Plugin VN-Calendar Multiple Cross-Site Scripting Vulnerabilities (1.0)