Font Size Change

HOMEIT SecurityMeasures for Information Security VulnerabilitiesIPA/ISEC:Vulnerabilities:Security Alert for Vulnerability in MODx

PRINT PAGE

IT Security

IPA/ISEC:Vulnerabilities:Security Alert for Vulnerability in MODx


Published: April 8, 2010
>> JAPANESE

Information-technology Promotion Agency, Japan (IPA, Chairman Koji Nishigaki) has issued a security alert concerning security vulnerability in MODx on April 8, 2010.
This vulnerability allows an attacker to execute arbitrary SQL commands on an affected system. If exploited, information held in the MODx database could be wrongly accessed and by the attacker, resulting in information being leaked, altered or deleted.
To fix this vulnerability, update the software to the fixed version provided by the product developer.

1.Overview

MODx is an open source content management system software developed by the MODx CMS Project. MODx is vulnerable to SQL Injection due to improper data processing. If exploited, information held in the MODx database could be wrongly accessed by a malicious attacker, resulting in information being leaked, altered or deleted.

For detailed information, refer to the following URL:
http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304

For the latest information, refer to the following URL:
http://jvndb.jvn.jp/jvndb/JVNDB-2010-000012

The IPA first received a report concerning this vulnerability through the creditee below on November 17, 2008, and the JPCERT Coordination Center (JPCERT/CC), in line with the Information Security Early Warning Partnership, made adjustments to clarify the matter with the vendor and made the announcement public on April 8, 2010.
Credit: Takeshi Terada, Mitsui Bussan Secure Directions, Inc.

2.Impact

When a website created by MODx is targeted by SQL injection attacks, information held in the MODx database could be accessed by a malicious attacker, resulting in information being leaked, altered or deleted.

Security Alert for Vulnerability in OpenPNE

3.Solution

To fix this vulnerability, update the software to the fixed version provided by the product developer.

4.CVSS Severity

(1)Evaluation Result

Severity Rating
(CVSS base score)
□ Low
(0.0~3.9)
□ Medium
(4.0~6.9)
■ High
(7.0~10.0)
CVSS base score    
7.5

(2) Base Score Metrics

AV:Access Vector □ Local □ Adjacent
 Network
■ Network
AC:Access Complexity □ High □ Medium ■ Low
Au:Authentication □ Multiple □ Single ■ None
C:Confidentiality Impact □ None ■ Partial □ Complete
I:Integrity Impact □ None ■ Partial □ Complete
A:Availability Impact □ None ■ Partial □ Complete

■:Selected Values

5.CWE Type

This vulnerability has been CWE classified as "SQL Injection (CWE-89)".

Contact

IT Security Center,
Information-technology Promotion Agency, Japan (ISEC/IPA)
E-mail: