VYPR
High severity7.3NVD Advisory· Published Dec 24, 2016· Updated May 6, 2026

CVE-2016-10037

CVE-2016-10037

Description

Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.

Affected products

1
  • cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*
    Range: <2.5.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.