CVE-2008-7242: XSS
Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachable from manager/index.php; (5) highlight, (6) id, (7) email, (8) name, and (9) parent parameters to index.php; and the (10) docgrp and (11) moreResultsPage parameters to index-ajax.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7242?
CVE-2008-7242 has a moderate severity rating due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2008-7242?
To fix CVE-2008-7242, upgrade your MODx CMS to the latest version that addresses these XSS vulnerabilities.
What software versions are affected by CVE-2008-7242?
CVE-2008-7242 affects MODx CMS versions 0.9.6.1 and 0.9.6.1-p1.
What type of vulnerability is CVE-2008-7242?
CVE-2008-7242 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2008-7242 be exploited by unauthenticated users?
Yes, CVE-2008-7242 can be exploited by unauthenticated remote attackers.