Description
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ad Invalid Click Protector (AICP) Malicious Code (1.2.9)
PrestaShop Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2021-21302)
WordPress Plugin Broken Link Checker Cross-Site Scripting (1.10.8)
WordPress 2.6.3 Cross-Site Scripting Vulnerability (0.6.2 - 2.6.3)