Description
SQL injection vulnerability in index.php in MODx 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the searchid parameter. NOTE: some of these details are obtained from third party information.
References (6)
Core 6
Core References
Third Party Advisory third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000005.html
Third Party Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN72630020/index.html
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/33182
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47840
Release Notes x_refsource_confirm
http://svn.modxcms.com/svn/tattoo/tattoo/releases/0.9.6.3/install/changelog.txt
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33405
Scores
EPSS
0.0118
EPSS Percentile
64.5%
Details
CWE
CWE-89
Status
published
Products (7)
modxcms/modxcms
0.9.0
modxcms/modxcms
0.9.1
modxcms/modxcms
0.9.2.1
modxcms/modxcms
0.9.5
modxcms/modxcms
0.9.6
modxcms/modxcms
0.9.6.1
modxcms/modxcms
< 0.9.6.2
Published
Jan 22, 2009
Tracked Since
Feb 18, 2026