HOMEIT SecurityMeasures for Information Security VulnerabilitiesIPA/ISEC:Vulnerabilities:Security Alert for Vulnerability in MODx
Published: April 8, 2010
>> JAPANESE
Information-technology Promotion Agency, Japan (IPA, Chairman Koji Nishigaki) has issued a security alert concerning security vulnerability in MODx on April 8, 2010.
This vulnerability allows an attacker to execute arbitrary SQL commands on an affected system. If exploited, information held in the MODx database could be wrongly accessed and by the attacker, resulting in information being leaked, altered or deleted.
To fix this vulnerability, update the software to the fixed version provided by the product developer.
MODx is an open source content management system software developed by the MODx CMS Project. MODx is vulnerable to SQL Injection due to improper data processing. If exploited, information held in the MODx database could be wrongly accessed by a malicious attacker, resulting in information being leaked, altered or deleted.
For detailed information, refer to the following URL:
http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304
For the latest information, refer to the following URL:
http://jvndb.jvn.jp/jvndb/JVNDB-2010-000012
The IPA first received a report concerning this vulnerability through the creditee below on November 17, 2008, and the JPCERT Coordination Center (JPCERT/CC), in line with the Information Security Early Warning Partnership, made adjustments to clarify the matter with the vendor and made the announcement public on April 8, 2010.
Credit: Takeshi Terada, Mitsui Bussan Secure Directions, Inc.
When a website created by MODx is targeted by SQL injection attacks, information held in the MODx database could be accessed by a malicious attacker, resulting in information being leaked, altered or deleted.
To fix this vulnerability, update the software to the fixed version provided by the product developer.
Severity Rating (CVSS base score) |
□ Low (0.0~3.9) |
□ Medium (4.0~6.9) |
■ High (7.0~10.0) |
---|---|---|---|
CVSS base score | 7.5 |
AV:Access Vector | □ Local | □ Adjacent Network |
■ Network |
---|---|---|---|
AC:Access Complexity | □ High | □ Medium | ■ Low |
Au:Authentication | □ Multiple | □ Single | ■ None |
C:Confidentiality Impact | □ None | ■ Partial | □ Complete |
I:Integrity Impact | □ None | ■ Partial | □ Complete |
A:Availability Impact | □ None | ■ Partial | □ Complete |
■:Selected Values
This vulnerability has been CWE classified as "SQL Injection (CWE-89)".
IT Security Center,
Information-technology Promotion Agency, Japan (ISEC/IPA)
E-mail: