CVE-2008-5940

MODx <0.9.6.2 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in index.php in MODx 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the searchid parameter. NOTE: some of these details are obtained from third party information.

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000005.html
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN72630020/index.html
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33182
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47840
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33405

Scores

EPSS 0.0118
EPSS Percentile 64.5%

Details

CWE
CWE-89
Status published
Products (7)
modxcms/modxcms 0.9.0
modxcms/modxcms 0.9.1
modxcms/modxcms 0.9.2.1
modxcms/modxcms 0.9.5
modxcms/modxcms 0.9.6
modxcms/modxcms 0.9.6.1
modxcms/modxcms < 0.9.6.2
Published Jan 22, 2009
Tracked Since Feb 18, 2026