<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0" xml:lang="en">
    <channel>
        <title>MODX Community Forums - Security Notices</title>
        <link>http://forums.modx.com/board/?board=8</link>
        <description><![CDATA[RSS Feed for MODX Community Forums]]></description>
        <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/modxsecurity" /><feedburner:info uri="modxsecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>modxsecurity</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
    <title><![CDATA[MODx Evo 1.0.4 (and prior) SQL Injection and Directory Traversal Vulnerabities]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/RmGJraioWuw/modx-evo-1-0-4-and-prior-sql-injection-and-directory-traversal-vulnerabities</link>
    <description>Status: SolvedProduct: MODx EvolutionSeverity: HighVersions: 1.0.4 and priorAdvisory Date: 2011-01-26Fixed Date: 2011-01-19Impact: a) A remote attacker may access or view arbitrary files on the server. b) A remote attacker may execute arbitrary PHP code as a result of SQL injection.DescriptionJPCERT/CC has issued the following advisories: a) http://jvn.jp/en/jp/JVN95385972/index.html b) http://jvn.jp/en/jp/JVN54092716/index.htmlSolutionUpgrade to MODx Revolution 1.0.5 available here:&amp;nbsp; http:...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/RmGJraioWuw" height="1" width="1"/&gt;</description>
    <author>21257</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/268/modx-evo-1-0-4-and-prior-sql-injection-and-directory-traversal-vulnerabities#dis-post-1674</comments>
    <pubDate>Fri, 28 Jan 2011 02:13:31 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/268/modx-evo-1-0-4-and-prior-sql-injection-and-directory-traversal-vulnerabities#dis-post-1674</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/268/modx-evo-1-0-4-and-prior-sql-injection-and-directory-traversal-vulnerabities#dis-post-1674</feedburner:origLink></item>
<item>
    <title><![CDATA[Critical PHP Bug Security Notice and Patch]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/VqW3tQrGiXc/critical-php-bug-security-notice-and-patch</link>
    <description>Earlier this week, a PHP Security Notice was made due to a critical bug in PHP that could cause PHP to fail should a value of 2.2250738585072011e-308 be set to a PHP value.More information can be found here:http://bugs.php.net/bug.php?id=53632http://www.exploringbinary.com/php-hangs-on-numeric-value-2-2250738585072011e-308This bug can affect MODx installations. MODx Revolution has been patched in GitHub for this. It is highly recommended that all MODx Revolution users patch their MODx installati...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/VqW3tQrGiXc" height="1" width="1"/&gt;</description>
    <author>28215</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/267/critical-php-bug-security-notice-and-patch#dis-post-1673</comments>
    <pubDate>Thu, 06 Jan 2011 09:43:30 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/267/critical-php-bug-security-notice-and-patch#dis-post-1673</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/267/critical-php-bug-security-notice-and-patch#dis-post-1673</feedburner:origLink></item>
<item>
    <title><![CDATA[Critical Security Upgrade Notice for FormIt, Quip and Login]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/bEosSsNBUAY/critical-security-upgrade-notice-for-formit-quip-and-login</link>
    <description>We received a report of a potential vulnerability in FormIt, Quip and Login that could be used to expose system settings including database information. This has been been corrected and new versions have been posted. Upgrading of FormIt, Login and Quip to the latest versions via Package Manager should be considered critical.This only affects MODX Revolution installations that have installed the Extras FormIt, Quip and Login.&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/bEosSsNBUAY" height="1" width="1"/&gt;</description>
    <author>27708</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/266/critical-security-upgrade-notice-for-formit-quip-and-login#dis-post-1672</comments>
    <pubDate>Thu, 09 Dec 2010 08:17:16 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/266/critical-security-upgrade-notice-for-formit-quip-and-login#dis-post-1672</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/266/critical-security-upgrade-notice-for-formit-quip-and-login#dis-post-1672</feedburner:origLink></item>
<item>
    <title><![CDATA[phpThumb  Command-Injection Vulnerability]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/MitMh5pwrug/phpthumb-command-injection-vulnerability</link>
    <description>It has recently come to our attention that phpThumb (all versions) contains an unpatched vulnerability.&amp;#039; parameter in the &amp;#039;phpThumb.php&amp;#039; script. Attackers can exploit this issue to execute arbitrary commands in the context of the webserver.Note that successful exploitation requires &amp;#039;ImageMagick&amp;#039; to be installed.phpThumb() 1.7.9 is affected; other versions may also be vulnerable.If you are using phpThumb on any of your sites either as part of a plugin or standalone, you s...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/MitMh5pwrug" height="1" width="1"/&gt;</description>
    <author>27708</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/265/phpthumb-command-injection-vulnerability#dis-post-1671</comments>
    <pubDate>Tue, 05 Oct 2010 11:01:07 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/265/phpthumb-command-injection-vulnerability#dis-post-1671</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/265/phpthumb-command-injection-vulnerability#dis-post-1671</feedburner:origLink></item>
<item>
    <title><![CDATA[MODx Revolution 2.0.3 Addresses Pair of Vulnerabilities]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/m0rASfYSxHU/modx-revolution-2-0-3-addresses-pair-of-vulnerabilities</link>
    <description>The MODx Revolution 2.0.3 release addresses a pair of reported security vulnerabilities with MODx Revolution 2.0.2-pl and possibly earlier releases:Input passed via the &amp;quot;modhash&amp;quot; parameter to manager/index.php is not properly sanitized before being returned to the user and input passed via the &amp;quot;class_key&amp;quot; parameter to manager/controllers/default/resource/tvs.php is not properly verified before being used to include files.We recommend that anyone running previous versions of M...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/m0rASfYSxHU" height="1" width="1"/&gt;</description>
    <author>27708</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/264/modx-revolution-2-0-3-addresses-pair-of-vulnerabilities#dis-post-1670</comments>
    <pubDate>Thu, 30 Sep 2010 01:47:17 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/264/modx-revolution-2-0-3-addresses-pair-of-vulnerabilities#dis-post-1670</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/264/modx-revolution-2-0-3-addresses-pair-of-vulnerabilities#dis-post-1670</feedburner:origLink></item>
<item>
    <title><![CDATA[MODx Revolution Cross-Site Scripting and Local File Inclusion Vulnerabilities]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/7jjRbo-Hfbk/modx-revolution-cross-site-scripting-and-local-file-inclusion-vulnerabilities</link>
    <description>Status: Solved (See: Notice on fix)Product: MODx RevolutionRisk: ModerateVersions: 2.0.xVunerability type: Cross-Site Scripting and Local File Inclusion VulnerabilitiesReport Date: 2010-09-29Fixed Date: 2010-09-29DescriptionIssue reported as Secunia Advisory SA41638. Input passed via the &amp;quot;modahsh&amp;quot; parameter to manager/index.php is not properly sanitized before being returned to the user and input passed via the &amp;quot;class_key&amp;quot; parameter to manager/controllers/default/resource/tvs...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/7jjRbo-Hfbk" height="1" width="1"/&gt;</description>
    <author>27708</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/263/modx-revolution-cross-site-scripting-and-local-file-inclusion-vulnerabilities#dis-post-1669</comments>
    <pubDate>Wed, 29 Sep 2010 02:50:16 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/263/modx-revolution-cross-site-scripting-and-local-file-inclusion-vulnerabilities#dis-post-1669</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/263/modx-revolution-cross-site-scripting-and-local-file-inclusion-vulnerabilities#dis-post-1669</feedburner:origLink></item>
<item>
    <title><![CDATA[MODx Evolution SQL Injection Vulnerability]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/S7qmAoBgcFY/modx-evolution-sql-injection-vulnerability</link>
    <description>Product: MODx EvolutionRisk: ModerateVersions: 1.0.3 and all previous releasesVunerability type: SQL InjectionReport Date: 2010-May-28Fixed Date: 2010-May-28DescriptionIssue reported as HTB22412. Attacker could potentially compromise MODx Evolution via an unsanitized variable on the /manager/index.php. &amp;nbsp; &amp;nbsp; No actual destructive exploit has yet been created or proven. The proof of concept offered on the htbridge.ch site, and variants, can only cause a SQL error to be displayed.Affected ...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/S7qmAoBgcFY" height="1" width="1"/&gt;</description>
    <author>27708</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/262/modx-evolution-sql-injection-vulnerability#dis-post-1668</comments>
    <pubDate>Mon, 07 Jun 2010 04:59:22 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/262/modx-evolution-sql-injection-vulnerability#dis-post-1668</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/262/modx-evolution-sql-injection-vulnerability#dis-post-1668</feedburner:origLink></item>
<item>
    <title><![CDATA[Security updates in MODx Evolution 1.0.3. You really should upgrade.]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/0K0co-E6krw/security-updates-in-modx-evolution-1-0-3-you-really-should-upgrade</link>
    <description>The MODx Evolution 1.0.3 release addresses a number of reported security vulnerabilities with previous MODx Evolution 1.0.2 and earlier releases: XSS possibilities with the SearchHighlight plugin (used by AjaxSearch) as reported in JVN#19774883 and JVN#46669729 Unwanted information disclosure about the site structure in the TinyMCE plugin SQL Injection via WebLoginWe strongly recommend that anyone running previous versions of MODx Evolution (including 0.9.x releases) consider Evolution 1.0.3 a m...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/0K0co-E6krw" height="1" width="1"/&gt;</description>
    <author>25663</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/261/security-updates-in-modx-evolution-1-0-3-you-really-should-upgrade#dis-post-1667</comments>
    <pubDate>Thu, 01 Apr 2010 10:11:06 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/261/security-updates-in-modx-evolution-1-0-3-you-really-should-upgrade#dis-post-1667</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/261/security-updates-in-modx-evolution-1-0-3-you-really-should-upgrade#dis-post-1667</feedburner:origLink></item>
<item>
    <title><![CDATA[Security Fix for MODx Revolution 2.0-beta2 (and beta1)]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/sZCrCfB4l4U/security-fix-for-modx-revolution-2-0-beta2-and-beta1</link>
    <description>There has been a reported security vulnerability for MODx Revolution 2.0 beta1 and beta2. We have committed a temporary fix until we hit the root of the issue, which is a problem with the modAccessibleObject and Context Policy loading.SVN users, to fix this vulnerability, please update to r5505.Non-SVN users, please make the changes as illustrated here:http://svn.modxcms.com/crucible/changelog/modx/?cs=5501 and here:http://svn.modxcms.com/crucible/changelog/modx/?cs=5505Again, MODx recommends th...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/sZCrCfB4l4U" height="1" width="1"/&gt;</description>
    <author>28215</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/260/security-fix-for-modx-revolution-2-0-beta2-and-beta1#dis-post-1666</comments>
    <pubDate>Thu, 23 Jul 2009 02:28:34 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/260/security-fix-for-modx-revolution-2-0-beta2-and-beta1#dis-post-1666</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/260/security-fix-for-modx-revolution-2-0-beta2-and-beta1#dis-post-1666</feedburner:origLink></item>
<item>
    <title><![CDATA[Reflect RFI Exploit]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/ummLkT9k5BI/reflect-rfi-exploit</link>
    <description>It has come to our attention that it&amp;#039;s possible to compromise some sites with specific server configurations via the reference copy of the Reflect snippet installed by default at /assets/snippets/reflect/snippet.reflect.phpA temporary solution is to simply rename this file with a .txt extension in your website. We are working on confirming a permanent solution and will update this post as soon as possible with more details.For more information see the Secunia advisory and the discussion on ...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/ummLkT9k5BI" height="1" width="1"/&gt;</description>
    <author>25663</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/259/reflect-rfi-exploit#dis-post-1665</comments>
    <pubDate>Mon, 24 Nov 2008 04:46:49 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/259/reflect-rfi-exploit#dis-post-1665</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/259/reflect-rfi-exploit#dis-post-1665</feedburner:origLink></item>
<item>
    <title><![CDATA[0.9.6.2 HTTP_REFERER Checks and Potential CSRF Vulnerabilities]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/RT5Sn6koqFs/0-9-6-2-http-referer-checks-and-potential-csrf-vulnerabilities</link>
    <description>Some potential CSRF (Cross Site Request Forgery) vulnerabilities that require a valid manager session were identified in MODx 0.9.6.1-p2 and earlier versions and as a result, a new security feature to help protect your content managers from these types of attacks has been introduced with the release of 0.9.6.2.CSRF PotentialDetails of the kinds of attacks these vulnerabilities make possible are available in the associated bug report: #MODX-206.HTTP_REFERER SolutionTo prevent a majority of these ...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/RT5Sn6koqFs" height="1" width="1"/&gt;</description>
    <author>22303</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/258/0-9-6-2-http-referer-checks-and-potential-csrf-vulnerabilities#dis-post-1663</comments>
    <pubDate>Tue, 16 Sep 2008 12:45:11 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/258/0-9-6-2-http-referer-checks-and-potential-csrf-vulnerabilities#dis-post-1663</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/258/0-9-6-2-http-referer-checks-and-potential-csrf-vulnerabilities#dis-post-1663</feedburner:origLink></item>
<item>
    <title><![CDATA[Acknowledgment: [DSECRG-08-013] Modx 0.9.6.1, 0.9.6.1p1 Multiple Security Vulner]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/H1DETzULK7c/acknowledgment-dsecrg-08-013-modx-0-9-6-1-0-9-6-1p1-multiple-security-vulner</link>
    <description>The MODx team believes the following security notice is sophistical – plausible but misleading (some would refer to it as &amp;quot;FUD&amp;quot;). We are continuing further investigations. Modx 0.9.6.1, 0.9.6.1p1 Multiple Security Vulnerabilities To reproduce the security compromises listed above, a malicious hacker would first have to hijack a valid manager session, then convince someone to visit a link to the site with that session and their XSS content inserted. This could be of concern however in...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/H1DETzULK7c" height="1" width="1"/&gt;</description>
    <author>25663</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/257/acknowledgment-dsecrg-08-013-modx-0-9-6-1-0-9-6-1p1-multiple-security-vulner#dis-post-1662</comments>
    <pubDate>Wed, 13 Feb 2008 08:49:25 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/257/acknowledgment-dsecrg-08-013-modx-0-9-6-1-0-9-6-1p1-multiple-security-vulner#dis-post-1662</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/257/acknowledgment-dsecrg-08-013-modx-0-9-6-1-0-9-6-1p1-multiple-security-vulner#dis-post-1662</feedburner:origLink></item>
<item>
    <title><![CDATA[IMPORTANT: Two new vulnerabilities in 0.9.6.1]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/DT60DXI9g_s/important-two-new-vulnerabilities-in-0-9-6-1</link>
    <description>Please take notice that two security vulnerabilities have been reported and confirmed in 3rd-party scripts that are included in the MODx 0.9.6.1 distributions.&amp;nbsp; Please see http://www.securityfocus.com/archive/1/485707/30/0/threaded for details.You need to take immediate action to protect your site( s ).&amp;nbsp; For 0.9.6.1Go to http://svn.modxcms.com/trac/tattoo/changeset/3281 and you can choose from three options for applying the changes to your existing installations: download the zip archi...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/DT60DXI9g_s" height="1" width="1"/&gt;</description>
    <author>25663</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/256/important-two-new-vulnerabilities-in-0-9-6-1#dis-post-1660</comments>
    <pubDate>Tue, 22 Jan 2008 01:21:09 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/256/important-two-new-vulnerabilities-in-0-9-6-1#dis-post-1660</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/256/important-two-new-vulnerabilities-in-0-9-6-1#dis-post-1660</feedburner:origLink></item>
<item>
    <title><![CDATA[CVE-2007-5371 not a vulnerability, or how I learned to stop worrying & love FUD]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/U3AKF1bhIgM/cve-2007-5371-not-a-vulnerability-or-how-i-learned-to-stop-worrying-amp-love-fud</link>
    <description>FYI:A number of MODx users have contacted me in regards to the posting of a MODx vulnerability from bugtraq, that is now showing up in two prominent vulnerability databases as CVE-2007-5371 and BID 25983:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5371http://www.securityfocus.com/bid/25983We were never contacted by the poster, and after extensive analysis on our side, this vulnerability has been found to be 100% inaccurate; in fact, I believe it to be deliberate FUD.&amp;nbsp; No attack vectors hav...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/U3AKF1bhIgM" height="1" width="1"/&gt;</description>
    <author>22303</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/255/cve-2007-5371-not-a-vulnerability-or-how-i-learned-to-stop-worrying-amp-love-fud#dis-post-1657</comments>
    <pubDate>Sun, 14 Oct 2007 12:25:42 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/255/cve-2007-5371-not-a-vulnerability-or-how-i-learned-to-stop-worrying-amp-love-fud#dis-post-1657</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/255/cve-2007-5371-not-a-vulnerability-or-how-i-learned-to-stop-worrying-amp-love-fud#dis-post-1657</feedburner:origLink></item>
<item>
    <title><![CDATA[Ditto 2.0.2 XSS Vulnerability]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/apY8B5ZsOoc/ditto-2-0-2-xss-vulnerability</link>
    <description>It has come to my attention, thanks to forum user neroz, that there is a small XSS vulnerability in Ditto 2.0.2. Although 2.1 is nearly ready, I will be away for the next 10 days or so and do not wish to release something I will not be able to support. Therefore, I&amp;#039;ve created a patched version of Ditto 2.0.2, which has now been released as 2.0.3. If your site makes extensive use of javascript or cookies, it would be wise to update your Ditto install. Otherwise, stay tuned for Ditto 2.1 in t...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/apY8B5ZsOoc" height="1" width="1"/&gt;</description>
    <author>33337</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/254/ditto-2-0-2-xss-vulnerability#dis-post-1656</comments>
    <pubDate>Mon, 20 Aug 2007 04:05:44 -0500</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/254/ditto-2-0-2-xss-vulnerability#dis-post-1656</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/254/ditto-2-0-2-xss-vulnerability#dis-post-1656</feedburner:origLink></item>
<item>
    <title><![CDATA[Critical Security Measure]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/C3jWzx9Nm-Q/critical-security-measure</link>
    <description>Please immediately add the following to the top of any public install you may have running of any version of MODx, inside the opening PHP tag. This potential vulnerability only affects installations where the php.ini has register_globals set to ON. (Which is a no-no and security issue in and of itself!)In /manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php:if(!isset($_SESSION)) {&amp;nbsp; &amp;nbsp; die(&amp;quot;&amp;lt;b&amp;gt;INCLUDE_ORDERING_ERROR&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Please use the...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/C3jWzx9Nm-Q" height="1" width="1"/&gt;</description>
    <author>25663</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/250/critical-security-measure#dis-post-1648</comments>
    <pubDate>Wed, 10 Jan 2007 10:34:12 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/250/critical-security-measure#dis-post-1648</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/250/critical-security-measure#dis-post-1648</feedburner:origLink></item>
<item>
    <title><![CDATA[FileDownload exploit!]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/vowgI8RqyKc/filedownload-exploit</link>
    <description>VERY IMPORTANTIf you have added the FileDownload snippet to a MODx site, please remove this snippet from your sites immediately.&amp;nbsp; There is a known vulnerability in this component that can expose critical database credentials by allowing exploiters to download your config.inc.php file or any number of other critical files directly from your server.&amp;nbsp; A new version of the component will be available shortly that resolves this issue, but in the meantime, it is absolutely critical that you ...&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/vowgI8RqyKc" height="1" width="1"/&gt;</description>
    <author>25663</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/253/filedownload-exploit#dis-post-1654</comments>
    <pubDate>Sat, 30 Dec 2006 11:54:06 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/253/filedownload-exploit#dis-post-1654</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/253/filedownload-exploit#dis-post-1654</feedburner:origLink></item>
<item>
    <title><![CDATA[0.9.2.2 released]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/tdhi0XZZIhQ/0-9-2-2-released</link>
    <description>0.9.2.2 is an important release which contains some measures to prevent possible XSS exploits that have been back-ported from the pending 095 release. This should be considered a mandatory and immediate upgrade. Existing installs can use the patch distribution if you&amp;#039;re running 0.9.2.1. Earlier installs should use the full upgrade as outlined on the download page.Download 0.9.2.2&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/tdhi0XZZIhQ" height="1" width="1"/&gt;</description>
    <author>22303</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/252/0-9-2-2-released#dis-post-1651</comments>
    <pubDate>Mon, 06 Nov 2006 09:58:48 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/252/0-9-2-2-released#dis-post-1651</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/252/0-9-2-2-released#dis-post-1651</feedburner:origLink></item>
<item>
    <title><![CDATA[Security notice subscription options]]></title>
    <link>http://feedproxy.google.com/~r/modxsecurity/~3/eIvd8EjtoWg/security-notice-subscription-options</link>
    <description>Please subscribe to MODx Security notices via one or both of the following two methods (powered by Feeburner):RSS: http://feeds.feedburner.com/modxsecurityEmail: Subscribe to MODx Security Notices by Email&lt;img src="http://feeds.feedburner.com/~r/modxsecurity/~4/eIvd8EjtoWg" height="1" width="1"/&gt;</description>
    <author>25663</author>
    <category><![CDATA[General]]></category>
    <comments>http://forums.modx.com/http://forums.modx.com/thread/251/security-notice-subscription-options#dis-post-1649</comments>
    <pubDate>Mon, 06 Nov 2006 12:59:23 -0600</pubDate>
    <guid isPermaLink="false">http://forums.modx.com/http://forums.modx.com/thread/251/security-notice-subscription-options#dis-post-1649</guid>
<feedburner:origLink>http://forums.modx.com/http://forums.modx.com/thread/251/security-notice-subscription-options#dis-post-1649</feedburner:origLink></item>
    </channel>
</rss>

