Description
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.
Remediation
References
Related Vulnerabilities
PHP Resource Management Errors Vulnerability (CVE-2006-1549)
WordPress Plugin EU Cookie Law for GDPR/CCPA Cross-Site Scripting (3.0.6)
Python Integer Overflow or Wraparound Vulnerability (CVE-2008-4864)
WordPress Plugin Simple Video Embedder Cross-Site Scripting (2.2)
WordPress Plugin NextGEN Gallery-WordPress Gallery Local File Inclusion (2.1.7)