Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Modxcms | Modxcms | 0.9.1 (including) | 0.9.1 (including) |