Vulnerabilities > Maxdev > Mdpro > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-07-27 | CVE-2009-2618 | SQL Injection vulnerability in Maxdev Mdpro 1.083 SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results action to modules.php. | 7.5 |
2007-01-31 | CVE-2007-0623 | SQL Injection vulnerability in Maxdev Mdpro 1.0.76 SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter. | 7.5 |