Vulnerabilities > CVE-2006-1821 - Directory Traversal vulnerability in Modxcms 0.9.1

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
modxcms
nessus
exploit available

Summary

Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter. To address this issue, the vendor has released a patch available at the following location: http://modxcms.com/forums/index.php/topic,3982.0.html

Vulnerable Configurations

Part Description Count
Application
Modxcms
1

Exploit-Db

descriptionMODxCMS 0.9.1 Index.PHP Directory Traversal Vulnerability. CVE-2006-1821. Webapps exploit for php platform
idEDB-ID:27649
last seen2016-02-03
modified2006-04-14
published2006-04-14
reporterRusydi Hasan
sourcehttps://www.exploit-db.com/download/27649/
titleMODxCMS 0.9.1 Index.PHP Directory Traversal Vulnerability

Nessus

NASL familyCGI abuses
NASL idMODX_091A.NASL
descriptionThe remote host is running MODx, a content management system written in PHP. The version of MODx installed on the remote host fails to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id21235
published2006-04-17
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/21235
titleMODx < 0.9.1a Multiple Vulnerabilities