CVE-2017-9067

Publication date

2017-05-18 16:00:00

Family

mitre

State

PUBLISHED

Description

In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.