Description
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
Remediation
References
Related Vulnerabilities
OpenSSL Other Vulnerability (CVE-2002-0659)
WordPress Plugin Twitter Friends Widget Cross-Site Scripting (3.1)
WordPress Plugin WordPress Facebook SQL Injection (1.0.8)
MySQL CVE-2021-35607 Vulnerability (CVE-2021-35607)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4198)