First published: Thu Apr 15 2010(Updated: )
SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MODx CMS Evolution | =0.9.6.1-p1 | |
MODx CMS Evolution | =0.9.2.1 | |
MODx CMS Evolution | =0.9.6.2 | |
MODx CMS Evolution | =0.9.0 | |
MODx CMS Evolution | =0.9.6 | |
MODx CMS Evolution | =0.9.1 | |
MODx CMS Evolution | <=1.0.2 | |
MODx CMS Evolution | =0.9.6.1 | |
MODx CMS Evolution | =0.9.5 | |
<=1.0.2 | ||
=0.9.0 | ||
=0.9.1 | ||
=0.9.2.1 | ||
=0.9.5 | ||
=0.9.6 | ||
=0.9.6.1 | ||
=0.9.6.1-p1 | ||
=0.9.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1426 has a high severity rating due to its potential for SQL injection attacks.
To fix CVE-2010-1426, upgrade MODx Evolution to version 1.0.3 or later.
CVE-2010-1426 affects all MODx Evolution versions prior to 1.0.3, including versions 0.9.0 to 0.9.6.2.
An attacker could execute arbitrary SQL commands, potentially compromising the database.
Yes, there are known exploits that take advantage of the SQL injection vulnerability in CVE-2010-1426.