CVE-2017-9067

Source
https://cve.org/CVERecord?id=CVE-2017-9067
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9067.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-9067
Aliases
Published
2017-05-18T16:29:00.157Z
Modified
2026-02-08T04:00:51.267345Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.

References

Affected packages

Git / github.com/modxcms/revolution

Affected ranges

Type
GIT
Repo
https://github.com/modxcms/revolution
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v2.*
v2.0.1-pl
v2.0.3-pl
v2.0.4-pl
v2.0.4-pl2
v2.0.5-pl
v2.0.6-pl
v2.0.6-pl2
v2.0.7-pl
v2.0.8-pl
v2.1.0-pl
v2.1.0-rc1
v2.1.0-rc2
v2.1.0-rc3
v2.1.0-rc4
v2.1.1-pl
v2.1.2-pl
v2.1.3-pl
v2.1.4-pl
v2.1.5-pl
v2.2.0-pl
v2.2.0-pl2
v2.2.0-rc1
v2.2.0-rc2
v2.2.0-rc3
v2.2.1-pl
v2.2.10-pl
v2.2.11-pl
v2.2.12-pl
v2.2.13-pl
v2.2.14-pl
v2.2.15-pl
v2.2.2-pl
v2.2.3-pl
v2.2.4-pl
v2.2.5-pl
v2.2.6-pl
v2.2.7-pl
v2.2.8-pl
v2.2.9-pl
v2.3.0-pl
v2.3.1-pl
v2.3.2-pl
v2.3.3-pl
v2.3.4-pl
v2.3.5-pl
v2.3.6-pl
v2.4.0-rc1
v2.4.1-pl
v2.4.2-pl
v2.4.3-pl
v2.4.4-pl
v2.5.0-pl
v2.5.0-rc1
v2.5.0-rc2
v2.5.1-pl
v2.5.2-pl
v2.5.3-pl
v2.5.4-pl
v2.5.5-pl
v2.5.6-pl

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9067.json"

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9067.json"