Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-5278

Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.234
EPSS Ranking 95.7%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2010-5278


Contact Us

Shodan ® - All rights reserved