Description
SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin.
References (5)
Core 5
Core References
Patch third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN19774883/index.html
Patch third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000012.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/39298
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/57636
Various Sources x_refsource_confirm
http://modxcms.com/forums/index.php/topic%2C47759.msg280304.html#msg280304
Scores
EPSS
0.0110
EPSS Percentile
62.2%
Details
CWE
CWE-89
Status
published
Products (8)
modxcms/modxcms
0.9.0
modxcms/modxcms
0.9.1
modxcms/modxcms
0.9.2.1
modxcms/modxcms
0.9.5
modxcms/modxcms
0.9.6
modxcms/modxcms
0.9.6.1 (2 CPE variants)
modxcms/modxcms
0.9.6.2
modxcms/modxcms
< 1.0.2
Published
Apr 15, 2010
Tracked Since
Feb 18, 2026