30186: MODx Thumbnail.php base_path Parameter Remote ...
MODx contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to Thumbnail.php not properly sanitizing user input supplied to the 'base_path ... http://osvdb.org/30186
connectors software vulnerabilities connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 ... vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in ... http://vulnerabilities.aspcode.net/connectors.aspx
Print Page - Critical Security Measure
... where the php.ini has register_globals set to ON. (Which is a no-no and security issue in and of itself!) In /manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php: http://modxcms.com/forums/index.php?action=printpage;topic=8604...
Critical Security Measure
In /manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php: Quote if(!isset($_SESSION['mgrValidated'])) { die("<b>INCLUDE_ORDERING_ERROR</b><br /><br />Please use the ... http://modxcms.com/forums/index.php?topic=8604.0;wap2