Maxdev / MD-Pro
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2006-5565 | CRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2) file, (3… | MEDIUM | 5.0 | Oct 27, 2006 |
| CVE-2006-5564 | Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op paramete… | MEDIUM | 4.3 | Oct 27, 2006 |
| CVE-2006-4964 | Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors… | MEDIUM | 6.8 | Sep 23, 2006 |
| CVE-2006-1677 | MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to… | MEDIUM | 6.4 | Apr 10, 2006 |
| CVE-2006-1676 | SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076,… | MEDIUM | 6.4 | Apr 10, 2006 |
| CVE-2005-2887 | MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2) AutoThem… | MEDIUM | 5.0 | Sep 14, 2005 |
| CVE-2005-2885 | The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could all… | HIGH | 7.5 | Sep 14, 2005 |
| CVE-2005-2840 | Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Download, (2… | HIGH | 10.0 | Sep 7, 2005 |
| CVE-2005-2839 | Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php… | MEDIUM | 4.3 | Sep 7, 2005 |
Showing 1 to 9 of 9 CVEs