First published: Wed Feb 02 2011(Updated: )
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
MODx CMS Evolution | <=1.0.4 | |
MODx CMS Evolution | =0.9.0 | |
MODx CMS Evolution | =0.9.1 | |
MODx CMS Evolution | =0.9.2.1 | |
MODx CMS Evolution | =0.9.5 | |
MODx CMS Evolution | =0.9.6 | |
MODx CMS Evolution | =0.9.6.1 | |
MODx CMS Evolution | =0.9.6.1-p1 | |
MODx CMS Evolution | =0.9.6.2 | |
MODx CMS Evolution | =1.0.2 | |
MODx CMS Evolution | =1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3929 is classified as a medium severity vulnerability due to its potential for arbitrary SQL command execution.
To fix CVE-2010-3929, you should upgrade to MODx Evolution version 1.0.5 or later.
CVE-2010-3929 affects MODx Evolution versions 1.0.4 and earlier, including specific earlier versions like 0.9.0 through 1.0.3.
CVE-2010-3929 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
CVE-2010-3929 can lead to unauthorized data access, data manipulation, and potentially full system compromise of affected web applications.