CVE-2008-7242
N/A
N/A
Summary
Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachable from manager/index.php; (5) highlight, (6) id, (7) email, (8) name, and (9) parent parameters to index.php; and the (10) docgrp and (11) moreResultsPage parameters to index-ajax.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/archive/1/487696/100/200/threaded
- http://secunia.com/advisories/28840
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40375
- http://www.securityfocus.com/bid/27672
- http://osvdb.org/41232
References
- http://www.securityfocus.com/archive/1/487696/100/200/threaded
- http://secunia.com/advisories/28840
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40375
- http://www.securityfocus.com/bid/27672
- http://osvdb.org/41232
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.