CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2009-4577 HIGH

SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL commands via the c paramet…

CVSS 7.5 EPSS 1.17% Jan 6, 2010
CVE-2008-7038 HIGH

SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgal…

CVSS 7.5 EPSS 1.15% Aug 24, 2009
CVE-2009-2618 HIGH

SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the po…

CVSS 7.5 EPSS 0.96% Jul 27, 2009
CVE-2009-2307 HIGH

SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands v…

CVSS 7.5 EPSS 0.93% Jul 2, 2009
CVE-2009-0728 HIGH

SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 EPSS 0.95% Feb 24, 2009
CVE-2007-5222 HIGH

SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substrin…

CVSS 7.5 EPSS 1.65% Oct 5, 2007
CVE-2007-3938 HIGH

SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands…

CVSS 7.5 EPSS 1.24% Jul 21, 2007
CVE-2006-7112 MEDIUM

Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVl…

CVSS 6.0 EPSS 1.61% Mar 6, 2007
CVE-2007-0624 MEDIUM

user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname para…

CVSS 5.0 EPSS 1.27% Jan 31, 2007
CVE-2007-0623 HIGH

SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.

CVSS 7.5 EPSS 1.81% Jan 31, 2007
CVE-2006-6869 HIGH

Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_glo…

CVSS 9.3 EPSS 3.32% Jan 4, 2007
CVE-2006-5565 MEDIUM

CRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2) file, (3…

CVSS 5.0 EPSS 1.37% Oct 27, 2006
CVE-2006-5564 MEDIUM

Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op paramete…

CVSS 4.3 EPSS 1.66% Oct 27, 2006
CVE-2006-4964 MEDIUM

Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors…

CVSS 6.8 EPSS 1.41% Sep 23, 2006
CVE-2006-1677 MEDIUM

MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to…

CVSS 6.4 EPSS 1.49% Apr 10, 2006
CVE-2006-1676 MEDIUM

SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076,…

CVSS 6.4 EPSS 1.22% Apr 10, 2006
CVE-2005-2887 MEDIUM

MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2) AutoThem…

CVSS 5.0 EPSS 1.55% Sep 14, 2005
CVE-2005-2885 HIGH

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could all…

CVSS 7.5 EPSS 8.71% Sep 14, 2005
CVE-2005-2840 HIGH

Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Download, (2…

CVSS 10.0 EPSS 1.42% Sep 7, 2005
CVE-2005-2839 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php…

CVSS 4.3 EPSS 0.95% Sep 7, 2005

Showing 1 to 20 CVEs · page 1