Vulnerabilities > Maxdev
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-08-24 | CVE-2008-7038 | SQL Injection vulnerability in Maxdev MY Egallery SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.php. | 7.5 |
2009-07-27 | CVE-2009-2618 | SQL Injection vulnerability in Maxdev Mdpro 1.083 SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results action to modules.php. | 7.5 |
2009-07-02 | CVE-2009-2307 | SQL Injection vulnerability in Maxdev Cwguestbook SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php. | 7.5 |
2009-02-24 | CVE-2009-0728 | SQL Injection vulnerability in Maxdev MY Egallery SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php. | 7.5 |
2007-03-06 | CVE-2006-7112 | Path Traversal vulnerability in Maxdev Mdpro Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it. | 6.0 |
2007-01-31 | CVE-2007-0624 | Remote Security vulnerability in Maxdev Mdpro 1.0.76 user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation. | 5.0 |
2007-01-31 | CVE-2007-0623 | SQL Injection vulnerability in Maxdev Mdpro 1.0.76 SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter. | 7.5 |
2006-12-31 | CVE-2006-6869 | Local File Include vulnerability in MDForum PNSVLang Parameter Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. | 9.3 |
2006-10-27 | CVE-2006-5565 | HTTP Response Splitting vulnerability in MAXdev MD-Pro CRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2) file, (3) module, and (4) func parameters in (a) index.php; and the (5) file parameter in (b) modules.php. | 5.0 |
2006-10-27 | CVE-2006-5564 | Cross-Site Scripting vulnerability in MAXdev MD-Pro User.PHP Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. network maxdev | 4.3 |