SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
https://exchange.xforce.ibmcloud.com/vulnerabilities/65082
http://modxcms.com/forums/index.php/topic%2C60045.0.html