Description
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.
Remediation
References
Related Vulnerabilities
WordPress Plugin All-in-One WP Migration Remote Code Execution (2.0.2)
WordPress Plugin SlideDeck 2 Lite Responsive Content Slider Cross-Site Scripting (2.3.18)
WordPress Plugin Resume Submissions & Job Postings Cross-Site Scripting (2.5.3)
TYPO3 Improper Input Validation Vulnerability (CVE-2010-3667)