NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86195  CVE-2017-9071  In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.    2.6  Low  2017-06-03  2017-05-30  View
86194  CVE-2017-9070  In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.    3.5  Low  2017-06-03  2017-05-30  View
86193  CVE-2017-9069  In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.    6.5  Medium  2017-06-03  2017-05-30  View
86192  CVE-2017-9068  In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.    4.3  Medium  2017-06-03  2017-05-30  View
86191  CVE-2017-9067  In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.    4.4  Medium  2017-06-03  2017-05-31  View

Page 434 of 17672, showing 5 records out of 88360 total, starting on record 2166, ending on 2170

Actions